Skip to content

Commit e490ec6

Browse files
authored
1 parent 2da079b commit e490ec6

File tree

3 files changed

+33
-0
lines changed

3 files changed

+33
-0
lines changed

.github/minty.yaml

Lines changed: 31 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,31 @@
1+
version: 'minty.abcxyz.dev/v2'
2+
3+
rule:
4+
if: |-
5+
assertion.iss == 'https://token.actions.githubusercontent.com' &&
6+
assertion.organization_id == '93787867' &&
7+
assertion.repository_id == '560465650' &&
8+
assertion.ref == 'refs/heads/main'
9+
10+
scope:
11+
update-checksums:
12+
rule:
13+
if: |-
14+
assertion.workflow_ref.startsWith("abcxyz/secure-setup-terraform/.github/workflows/update-checksums.yml") &&
15+
(assertion.event_name == 'schedule' || assertion.event_name == 'workflow_dispatch')
16+
repositories:
17+
- 'secure-setup-terraform'
18+
permissions:
19+
pull_requests: 'write'
20+
contents: 'write'
21+
22+
create-release:
23+
rule:
24+
if: |-
25+
assertion.workflow_ref.startsWith("abcxyz/secure-setup-terraform/.github/workflows/create-release.yml") &&
26+
assertion.event_name == 'push'
27+
repositories:
28+
- 'secure-setup-terraform'
29+
permissions:
30+
contents: 'write'
31+

.github/workflows/create-release.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -60,6 +60,7 @@ jobs:
6060
service_url: '${{ vars.TOKEN_MINTER_SERVICE_URL }}'
6161
requested_permissions: |-
6262
{
63+
"scope": "create-release",
6364
"repositories": ["${{ github.event.repository.name }}"],
6465
"permissions": {
6566
"contents": "write"

.github/workflows/update-checksums.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -48,6 +48,7 @@ jobs:
4848
service_url: '${{ vars.TOKEN_MINTER_SERVICE_URL }}'
4949
requested_permissions: |-
5050
{
51+
"scope": "update-checksums",
5152
"repositories": ["secure-setup-terraform"],
5253
"permissions": {
5354
"pull_requests": "write",

0 commit comments

Comments
 (0)