Giter Club home page Giter Club logo

Comments (7)

mikehardy avatar mikehardy commented on August 14, 2024 1

probably because between then and now actions got access to the default token by putting it in the action.yaml so users were spared having to specify it. This is orthogonal though I think - it's about restricting that token to just the two perms of actions read/write and removing all the rest, which would be a nice way to reduce security surface area

from cancel-workflow-action.

tjenkinson avatar tjenkinson commented on August 14, 2024 1

It needs actions read as well, at least https://docs.github.com/en/rest/reference/permissions-required-for-github-apps#permission-on-actions

Yeh I think write includes read. Haven’t tried it yet (ref video-dev/hls.js#3874) but will report back if it works

from cancel-workflow-action.

mikehardy avatar mikehardy commented on August 14, 2024

It needs actions read as well, at least https://docs.github.com/en/rest/reference/permissions-required-for-github-apps#permission-on-actions

have you tried it with a restricted token? would be interesting to see if actions read/write really was sufficient - then I'm sure a PR to the docs could work, @styfle has merged everything reasonable I've seen get proposed based on my last look through here while integrating it :-)

from cancel-workflow-action.

styfle avatar styfle commented on August 14, 2024

I had more documentation earlier but I removed it for some reason, I can't remember why πŸ€”

https://github.com/styfle/cancel-workflow-action/blob/1ec9f13909cd1e75b4dab50f5491b45c70579fa6/README.md#usage

from cancel-workflow-action.

tjenkinson avatar tjenkinson commented on August 14, 2024

Looks like it worked. No errors in logs

from cancel-workflow-action.

adrienbernede avatar adrienbernede commented on August 14, 2024

I have been using it with apparent success in our project:
https://github.com/mfem/mfem/blob/c4d3610cb2e60501a9209eac2031453c9bb97383/.github/workflows/builds-and-tests.yml#L76

Being able to control the permission was the trigger to use this. Seeing this in documentation would be great. Thanks for this thread!

from cancel-workflow-action.

styfle avatar styfle commented on August 14, 2024

Great, feel free to submit a PR to update the README πŸ‘

from cancel-workflow-action.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.