From e95e59c1a9e38aca0548e08f2da018dfcf3df903 Mon Sep 17 00:00:00 2001 From: Venktesh Shivam Patel Date: Mon, 20 May 2024 15:26:18 +0100 Subject: [PATCH] add top level permission to gh action (#5584) --- .github/workflows/cherry-pick.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/cherry-pick.yml b/.github/workflows/cherry-pick.yml index a380d5e1c1..96582e790e 100644 --- a/.github/workflows/cherry-pick.yml +++ b/.github/workflows/cherry-pick.yml @@ -5,9 +5,15 @@ on: - main types: ["closed"] +permissions: + contents: read + jobs: cherry_pick_to_release: - runs-on: ubuntu-latest + permissions: + contents: write + pull-requests: write + runs-on: ubuntu-22.04 name: Cherry pick into release-3.5 if: ${{ contains(github.event.pull_request.labels.*.name, 'dependencies') && github.event.pull_request.merged == true }} steps: