Skip to content

Commit 9003701

Browse files
authored
FIX: Permissions issues fixed in docker-cached-build.yml (#21)
FIX: Permissions issues fixes as reported by dashboard in `docker-cached-build.yml` and `dependency-review.yml` - Scope the write permissions per job instead of globally. That includes permissions for security-events and packages write have been moved for each job independently. - Remove unused permissions. FIX: GitHub workflow issues in `build-baremetal-ubuntu.yml`: - Working directory in 2 tasks was set incorrectly. - Add missing `"` and `;` --------- Signed-off-by: Miłosz Linkiewicz <milosz.linkiewicz@intel.com>
1 parent 6b8b36c commit 9003701

3 files changed

Lines changed: 27 additions & 11 deletions

File tree

.github/workflows/build-baremetal-ubuntu.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ jobs:
8888
-DCMAKE_CXX_FLAGS="-I/opt/intel/oneapi/ipp/latest/include -I/opt/intel/oneapi/ipp/latest/include/ipp"
8989
9090
- name: 'Configure ffmpeg repository'
91-
working-directory: "${BUILD_DIR}/ffmpeg"
91+
working-directory: "ffmpeg"
9292
continue-on-error: true
9393
run: |
9494
./configure \
@@ -106,10 +106,10 @@ jobs:
106106
--extra-ldflags="-fopenmp -L/opt/intel/oneapi/ipp/latest/lib -L${PREFIX}/lib" \
107107
--enable-cross-compile \
108108
--prefix="${PREFIX}" || \
109-
{ tail -n 100 "${BUILD_DIR}/ffmpeg/ffbuild/config.log && exit 1 }
109+
{ tail -n 100 "${BUILD_DIR}/ffmpeg/ffbuild/config.log" && exit 1; }
110110
111111
- name: 'Build, install and check ffmpeg'
112-
working-directory: "${BUILD_DIR}/ffmpeg"
112+
working-directory: "ffmpeg"
113113
continue-on-error: true
114114
run: |
115115
make clean

.github/workflows/dependency-review.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -33,9 +33,6 @@ jobs:
3333
runs-on: 'ubuntu-22.04'
3434
permissions:
3535
contents: read
36-
packages: read
37-
actions: read
38-
security-events: write
3936
timeout-minutes: 90
4037
env:
4138
SUPER_LINTER_OUTPUT_DIRECTORY_NAME: super-linter-output

.github/workflows/docker-cached-build.yml

Lines changed: 24 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -7,11 +7,6 @@ on:
77
branches: [ "main", "dev" ]
88
workflow_dispatch:
99

10-
permissions:
11-
contents: read
12-
security-events: write
13-
packages: write
14-
1510
concurrency:
1611
group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.sha }}
1712
cancel-in-progress: true
@@ -20,41 +15,65 @@ jobs:
2015
flex-ubuntu-2204-build:
2116
name: "Build Flex Ubuntu 22.04 Docker Image"
2217
uses: ./.github/workflows/template-docker-cached-build.yml
18+
permissions:
19+
security-events: write
20+
packages: write
21+
contents: read
2322
with:
2423
docker_file_path: "docker/Flex/Dockerfile.ubuntu22.04"
2524
docker_image_name: "raisr-flex-ubuntu-22.04"
2625

2726
xeon-ubuntu-1804-build:
2827
name: "Build Xeon Ubuntu 18.04 Docker Image"
2928
uses: ./.github/workflows/template-docker-cached-build.yml
29+
permissions:
30+
security-events: write
31+
packages: write
32+
contents: read
3033
with:
3134
docker_file_path: "docker/Xeon/Dockerfile.ubuntu18.04"
3235
docker_image_name: "raisr-xeon-ubuntu-18.04"
3336

3437
xeon-ubuntu-2004-build:
3538
name: "Build Xeon Ubuntu 20.04 Docker Image"
3639
uses: ./.github/workflows/template-docker-cached-build.yml
40+
permissions:
41+
security-events: write
42+
packages: write
43+
contents: read
3744
with:
3845
docker_file_path: "docker/Xeon/Dockerfile.ubuntu20.04"
3946
docker_image_name: "raisr-xeon-ubuntu-20.04"
4047

4148
xeon-ubuntu-2204-build:
4249
name: "Build Xeon Ubuntu 22.04 Docker Image"
4350
uses: ./.github/workflows/template-docker-cached-build.yml
51+
permissions:
52+
security-events: write
53+
packages: write
54+
contents: read
4455
with:
4556
docker_file_path: "docker/Xeon/Dockerfile.ubuntu22.04"
4657
docker_image_name: "raisr-xeon-ubuntu-22.04"
4758

4859
xeon-centos-stream9-build:
4960
name: "Build Xeon Centos Stream9 Docker Image"
5061
uses: ./.github/workflows/template-docker-cached-build.yml
62+
permissions:
63+
security-events: write
64+
packages: write
65+
contents: read
5166
with:
5267
docker_file_path: "docker/Xeon/Dockerfile.centos9"
5368
docker_image_name: "raisr-xeon-centos-9"
5469

5570
xeon-rockylinux-9-mini-build:
5671
name: "Build Xeon Rockylinux 9-mini Docker Image"
5772
uses: ./.github/workflows/template-docker-cached-build.yml
73+
permissions:
74+
security-events: write
75+
packages: write
76+
contents: read
5877
with:
5978
docker_file_path: "docker/Xeon/Dockerfile.rockylinux9-mini"
6079
docker_image_name: "raisr-xeon-rockylinux-9-mini"

0 commit comments

Comments
 (0)