32
32
33
33
- name : " Check and publish codeql-LANG-queries (src) pack"
34
34
env :
35
- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
35
+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
36
36
run : |
37
37
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-queries/versions --jq '.[0].metadata.container.tags[0]')
38
38
CURRENT_VERSION=$(grep version ${{ matrix.language }}/src/qlpack.yml | awk '{print $2}')
69
69
70
70
- name : " Check and publish codeql-LANG-libs (lib) pack"
71
71
env :
72
- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
72
+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
73
73
run : |
74
74
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-libs/versions --jq '.[0].metadata.container.tags[0]')
75
75
CURRENT_VERSION=$(grep version ${{ matrix.language }}/lib/qlpack.yml | awk '{print $2}')
84
84
extensions :
85
85
runs-on : ubuntu-latest
86
86
87
+ permissions :
88
+ contents : read
89
+ packages : write
90
+
87
91
strategy :
88
92
fail-fast : false
89
93
matrix :
@@ -102,7 +106,7 @@ jobs:
102
106
103
107
- name : Check and publish codeql-LANG-extensions (ext) pack
104
108
env :
105
- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
109
+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
106
110
run : |
107
111
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-extensions/versions --jq '.[0].metadata.container.tags[0]')
108
112
CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext/qlpack.yml | awk '{print $2}')
@@ -117,6 +121,10 @@ jobs:
117
121
library_sources_extensions :
118
122
runs-on : ubuntu-latest
119
123
124
+ permissions :
125
+ contents : read
126
+ packages : write
127
+
120
128
strategy :
121
129
fail-fast : false
122
130
matrix :
@@ -135,7 +143,7 @@ jobs:
135
143
136
144
- name : Check and publish codeql-LANG-library-sources (ext-library-sources) pack
137
145
env :
138
- GITHUB_TOKEN : ${{ secrets.GHCR_TOKEN }}
146
+ GITHUB_TOKEN : ${{ secrets.GITHUB_TOKEN }}
139
147
run : |
140
148
PUBLISHED_VERSION=$(gh api /orgs/githubsecuritylab/packages/container/codeql-${{ matrix.language }}-library-sources/versions --jq '.[0].metadata.container.tags[0]')
141
149
CURRENT_VERSION=$(grep version ${{ matrix.language }}/ext-library-sources/qlpack.yml | awk '{print $2}')
0 commit comments