From b719c32fd34e23a0f2e06845b813d7b4c84b2415 Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Tue, 6 Oct 2026 11:55:32 +0300 Subject: [PATCH 1/6] ci: restrict artifacts creation --- .github/workflows/ci.yml | 47 +++++++++++++++------- .github/workflows/publish.yml | 73 +++++++++++++++++++++-------------- docs/using-ci-builds.md | 16 ++++++-- 3 files changed, 89 insertions(+), 47 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 57503eb14..b479159b5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,6 +4,9 @@ concurrency: group: ${{github.workflow}}-${{github.event.pull_request.number || github.sha}} cancel-in-progress: true +permissions: + contents: read + on: push: branches-ignore: @@ -94,26 +97,19 @@ jobs: runs-on: ubuntu-latest env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1 + BUILD_CONFIGURATION: ${{ (github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'push' && github.ref == format('refs/heads/{0}', github.event.repository.default_branch)) && 'Release' || 'Debug' }} steps: + - uses: actions/checkout@v4 + - uses: actions/setup-dotnet@v4 + if: env.BUILD_CONFIGURATION == 'Release' with: dotnet-quality: ga dotnet-version: | 3.1 - 10.0 - - - uses: actions/checkout@v4 - - - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: | - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -L -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret ${{ env.RELEASE_KEY_SECRET }} + 10.0.x - run: node build/make-nojquery - run: node build/replace-meta "${{ github.run_number }}" "${{ github.ref }}" "${{ github.repository }}" @@ -121,15 +117,36 @@ jobs: - run: npm pack - run: npm pack ./js-nojquery - - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: dotnet pack net/DevExtreme.AspNet.Data --configuration=Release --include-symbols + - name: Prepare NuGet deps + if: env.BUILD_CONFIGURATION == 'Release' + env: + RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} + run: | + if [ -z "$RELEASE_KEY_SECRET" ]; then + echo "::error::RELEASE_KEY_SECRET is required." + exit 1 + fi + wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + curl -fL -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip + unzip /opt/secure-file.zip -d /opt/secure-file + dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret "$RELEASE_KEY_SECRET" + + - name: Pack NuGet package + run: | + dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + if [ "$BUILD_CONFIGURATION" = "Release" ]; then + rm -f net/DevExtreme.AspNet.Data/release.snk + fi - uses: actions/upload-artifact@v4 with: name: release-packages path: | - net/DevExtreme.AspNet.Data/bin/Release/*.nupkg + net/DevExtreme.AspNet.Data/bin/${{ env.BUILD_CONFIGURATION }}/*.nupkg devextreme-aspnet-data-*.tgz + retention-days: 14 + if-no-files-found: error docfx: runs-on: windows-latest diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 5d8471543..2509c22c7 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -8,6 +8,10 @@ on: type: boolean default: false +concurrency: + group: ${{ github.workflow }}-${{ github.ref }} + cancel-in-progress: false + permissions: contents: read @@ -20,34 +24,29 @@ env: jobs: pack: - runs-on: ubuntu-24.04 + if: github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'workflow_dispatch' && startsWith(github.ref, 'refs/tags/') + runs-on: ubuntu-latest + environment: nuget env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1 + BUILD_CONFIGURATION: Release steps: - - uses: actions/setup-dotnet@v4 + - uses: actions/checkout@v4 with: - dotnet-quality: ga - dotnet-version: | - 3.1 - 8.0 + persist-credentials: false - uses: actions/setup-node@v4 with: node-version: '24' - - uses: actions/checkout@v4 - - - name: Decrypt signing key - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: | - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -L -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret ${{ env.RELEASE_KEY_SECRET }} + - uses: actions/setup-dotnet@v4 + with: + dotnet-quality: ga + dotnet-version: | + 3.1 + 10.0.x - name: Build no-jquery package run: node build/make-nojquery @@ -60,27 +59,45 @@ jobs: npm pack npm pack ./js-nojquery - - name: Pack NuGet package - if: ${{ env.RELEASE_KEY_SECRET != '' }} - run: dotnet pack net/DevExtreme.AspNet.Data --configuration=Release --include-symbols + - name: Prepare NuGet deps + env: + RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} + run: | + if [ -z "$RELEASE_KEY_SECRET" ]; then + echo "::error::RELEASE_KEY_SECRET is required." + exit 1 + fi + wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + curl -fL -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip + unzip /opt/secure-file.zip -d /opt/secure-file + dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret "$RELEASE_KEY_SECRET" - - name: Upload NuGet packages as artifacts - if: ${{ env.RELEASE_KEY_SECRET != '' }} - uses: actions/upload-artifact@v4 - with: - name: nuget-packages - path: net/DevExtreme.AspNet.Data/bin/Release/*.nupkg + - name: Pack NuGet package + run: | + dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + rm -f net/DevExtreme.AspNet.Data/release.snk - name: Upload npm packages as artifacts uses: actions/upload-artifact@v4 with: name: npm-packages path: devextreme-aspnet-data-*.tgz + retention-days: 7 + if-no-files-found: error + + - name: Upload NuGet packages as artifacts + uses: actions/upload-artifact@v4 + with: + name: nuget-packages + path: net/DevExtreme.AspNet.Data/bin/${{ env.BUILD_CONFIGURATION }}/*.nupkg + retention-days: 7 + if-no-files-found: error publish: - runs-on: ubuntu-latest + runs-on: ubuntu-slim needs: pack - if: startsWith(github.ref, 'refs/tags/') + if: github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'workflow_dispatch' && startsWith(github.ref, 'refs/tags/') environment: npmjs permissions: contents: read diff --git a/docs/using-ci-builds.md b/docs/using-ci-builds.md index b7234105a..2a147c3d3 100644 --- a/docs/using-ci-builds.md +++ b/docs/using-ci-builds.md @@ -1,12 +1,14 @@ # Using CI Builds -You can download automated build artifacts [here](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/ci.yml?query=branch%3Amaster). Please note that you need to be signed in to GitHub. +You can download automated build artifacts [here](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/ci.yml?query=branch%3Amaster+event%3Apush). Please note that you need to be signed in to GitHub. - Click the most recent successful workflow run result. -- At the bottom of the opened page, download the `release-packages` archive. +- At the bottom of the opened page, download the `release-packages` archive for npm packages and the NuGet package and symbols. + +The `release-packages` archive from an upstream default-branch push contains the following files: -It contains the following files: - `net/DevExtreme.AspNet.Data/bin/Release/DevExtreme.AspNet.Data.99.0.0-ci-NNN.nupkg` +- `net/DevExtreme.AspNet.Data/bin/Release/DevExtreme.AspNet.Data.99.0.0-ci-NNN.symbols.nupkg` - `devextreme-aspnet-data-99.0.0-ci-NNN.tgz` - `devextreme-aspnet-data-nojquery-99.0.0-ci-NNN.tgz` @@ -30,11 +32,17 @@ Alternatively, you can get the JavaScript file directly [from the master branch] ## NuGet Package +The CI `release-packages` artifact is retained for 14 days and includes the NuGet package and symbols, built with the same CI version as the npm packages. Only pushes to the default branch (`master`) in the upstream `DevExpress/DevExtreme.AspNet.Data` repository produce Release NuGet packages containing strong-name-signed assemblies, with package version `99.0.0-ci-NNN`. Pull requests, other branch pushes, scheduled runs, manual CI runs, and fork runs produce Debug NuGet packages containing unsigned assemblies under `bin/Debug`, without preparing signing dependencies or accessing the signing secret. Fork package versions also include the fork owner name. + +For tagged releases, the [Publish workflow](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/publish.yml) runs only when manually dispatched against a tag in the upstream repository. Version tags set the package version. It saves NuGet packages containing strong-name-signed Release assemblies in `nuget-packages` and npm packages in `npm-packages`, each retained for 7 days. Dry runs also generate these artifacts but skip actual npm publishing. The workflow does not push packages to a NuGet registry. + Follow [these instructions](https://stackoverflow.com/q/10240029) to install the downloaded .nupkg file. ## Add an Assembly Binding Redirect -For .NET framework projects, add a binding redirect to the `web.config` or `app.config` file: +The following redirect applies to strong-name-signed Release assemblies. + +For .NET framework projects, use the assembly version of the downloaded package in place of `99.0.0.0` below and add a binding redirect to the `web.config` or `app.config` file: ```xml From 1b915a726d3463831943c8b19bb5e38b35fca1bc Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Wed, 7 Oct 2026 17:39:25 +0300 Subject: [PATCH 2/6] revert docs/using-ci-builds.md --- docs/using-ci-builds.md | 8 +------- 1 file changed, 1 insertion(+), 7 deletions(-) diff --git a/docs/using-ci-builds.md b/docs/using-ci-builds.md index 2a147c3d3..43cfe46d9 100644 --- a/docs/using-ci-builds.md +++ b/docs/using-ci-builds.md @@ -32,17 +32,11 @@ Alternatively, you can get the JavaScript file directly [from the master branch] ## NuGet Package -The CI `release-packages` artifact is retained for 14 days and includes the NuGet package and symbols, built with the same CI version as the npm packages. Only pushes to the default branch (`master`) in the upstream `DevExpress/DevExtreme.AspNet.Data` repository produce Release NuGet packages containing strong-name-signed assemblies, with package version `99.0.0-ci-NNN`. Pull requests, other branch pushes, scheduled runs, manual CI runs, and fork runs produce Debug NuGet packages containing unsigned assemblies under `bin/Debug`, without preparing signing dependencies or accessing the signing secret. Fork package versions also include the fork owner name. - -For tagged releases, the [Publish workflow](https://github.com/DevExpress/DevExtreme.AspNet.Data/actions/workflows/publish.yml) runs only when manually dispatched against a tag in the upstream repository. Version tags set the package version. It saves NuGet packages containing strong-name-signed Release assemblies in `nuget-packages` and npm packages in `npm-packages`, each retained for 7 days. Dry runs also generate these artifacts but skip actual npm publishing. The workflow does not push packages to a NuGet registry. - Follow [these instructions](https://stackoverflow.com/q/10240029) to install the downloaded .nupkg file. ## Add an Assembly Binding Redirect -The following redirect applies to strong-name-signed Release assemblies. - -For .NET framework projects, use the assembly version of the downloaded package in place of `99.0.0.0` below and add a binding redirect to the `web.config` or `app.config` file: +For .NET framework projects, add a binding redirect to the `web.config` or `app.config` file: ```xml From f9d81380cda84e904575b96b3e67d892bdcfcb6e Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Wed, 7 Oct 2026 20:04:04 +0300 Subject: [PATCH 3/6] extract to composite action --- .github/actions/prepare-nuget-deps/action.yml | 46 +++++++++++++++++++ .github/workflows/ci.yml | 24 ++-------- .github/workflows/publish.yml | 23 ++-------- 3 files changed, 54 insertions(+), 39 deletions(-) create mode 100644 .github/actions/prepare-nuget-deps/action.yml diff --git a/.github/actions/prepare-nuget-deps/action.yml b/.github/actions/prepare-nuget-deps/action.yml new file mode 100644 index 000000000..cc4479eea --- /dev/null +++ b/.github/actions/prepare-nuget-deps/action.yml @@ -0,0 +1,46 @@ +name: prepare-nuget-deps +description: Sets up Release NuGet packaging dependencies and decrypts supplied signing key + +inputs: + encrypted-key-path: + description: Path to encrypted signing key, relative to workspace + required: true + release-key-secret: + description: Password for encrypted signing key + required: true + +runs: + using: "composite" + + steps: + - uses: actions/setup-dotnet@v4 + with: + dotnet-quality: ga + dotnet-version: | + 3.1 + 10.0.x + + - name: Install Linux dependencies + if: runner.os == 'Linux' + shell: bash + run: | + wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb + + - name: Prepare secure-file tool + shell: bash + run: | + curl -fL -o "$RUNNER_TEMP/secure-file.zip" https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip + unzip "$RUNNER_TEMP/secure-file.zip" -d "$RUNNER_TEMP/secure-file" + + - name: Decrypt signing key + shell: bash + env: + ENCRYPTED_KEY_PATH: ${{ inputs.encrypted-key-path }} + RELEASE_KEY_SECRET: ${{ inputs.release-key-secret }} + run: | + if [ -z "$RELEASE_KEY_SECRET" ]; then + echo "::error::RELEASE_KEY_SECRET is required." + exit 1 + fi + dotnet "$RUNNER_TEMP/secure-file/secure-file.dll" -decrypt "$ENCRYPTED_KEY_PATH" -secret "$RELEASE_KEY_SECRET" diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index b479159b5..1f1377874 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -103,14 +103,6 @@ jobs: steps: - uses: actions/checkout@v4 - - uses: actions/setup-dotnet@v4 - if: env.BUILD_CONFIGURATION == 'Release' - with: - dotnet-quality: ga - dotnet-version: | - 3.1 - 10.0.x - - run: node build/make-nojquery - run: node build/replace-meta "${{ github.run_number }}" "${{ github.ref }}" "${{ github.repository }}" @@ -119,18 +111,10 @@ jobs: - name: Prepare NuGet deps if: env.BUILD_CONFIGURATION == 'Release' - env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} - run: | - if [ -z "$RELEASE_KEY_SECRET" ]; then - echo "::error::RELEASE_KEY_SECRET is required." - exit 1 - fi - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -fL -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret "$RELEASE_KEY_SECRET" + uses: ./.github/actions/prepare-nuget-deps + with: + encrypted-key-path: net/DevExtreme.AspNet.Data/release.snk.enc + release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package run: | diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 2509c22c7..cdb22b960 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -41,13 +41,6 @@ jobs: with: node-version: '24' - - uses: actions/setup-dotnet@v4 - with: - dotnet-quality: ga - dotnet-version: | - 3.1 - 10.0.x - - name: Build no-jquery package run: node build/make-nojquery @@ -60,18 +53,10 @@ jobs: npm pack ./js-nojquery - name: Prepare NuGet deps - env: - RELEASE_KEY_SECRET: ${{ secrets.RELEASE_KEY_SECRET }} - run: | - if [ -z "$RELEASE_KEY_SECRET" ]; then - echo "::error::RELEASE_KEY_SECRET is required." - exit 1 - fi - wget https://archive.ubuntu.com/ubuntu/pool/main/o/openssl1.0/libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - sudo dpkg -i libssl1.0.0_1.0.2n-1ubuntu5_amd64.deb - curl -fL -o /opt/secure-file.zip https://github.com/appveyor/secure-file/releases/download/1.0.1/secure-file.zip - unzip /opt/secure-file.zip -d /opt/secure-file - dotnet /opt/secure-file/secure-file.dll -decrypt net/DevExtreme.AspNet.Data/release.snk.enc -secret "$RELEASE_KEY_SECRET" + uses: ./.github/actions/prepare-nuget-deps + with: + encrypted-key-path: net/DevExtreme.AspNet.Data/release.snk.enc + release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package run: | From e6658b1fa7e03d104d33239b654d9f4460ebffe4 Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Wed, 7 Oct 2026 20:43:40 +0300 Subject: [PATCH 4/6] always remove snk with force, any build cfg --- .github/workflows/ci.yml | 10 +++++----- .github/workflows/publish.yml | 8 +++++--- 2 files changed, 10 insertions(+), 8 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 1f1377874..f7d88f2a0 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -117,11 +117,11 @@ jobs: release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package - run: | - dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols - if [ "$BUILD_CONFIGURATION" = "Release" ]; then - rm -f net/DevExtreme.AspNet.Data/release.snk - fi + run: dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + + - name: Remove signing key + if: always() + run: rm -f net/DevExtreme.AspNet.Data/release.snk - uses: actions/upload-artifact@v4 with: diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index cdb22b960..953fdb0a2 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -59,9 +59,11 @@ jobs: release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package - run: | - dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols - rm -f net/DevExtreme.AspNet.Data/release.snk + run: dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + + - name: Remove signing key + if: always() + run: rm -f net/DevExtreme.AspNet.Data/release.snk - name: Upload npm packages as artifacts uses: actions/upload-artifact@v4 From 65dc1aff4781049121ec78a7bb9871793171e22c Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Wed, 7 Oct 2026 20:56:33 +0300 Subject: [PATCH 5/6] shell --- .github/workflows/ci.yml | 3 ++- .github/workflows/publish.yml | 3 ++- 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index f7d88f2a0..69fb70ed7 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -117,10 +117,11 @@ jobs: release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package - run: dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + run: dotnet pack net/DevExtreme.AspNet.Data -c ${{ env.BUILD_CONFIGURATION }} --include-symbols - name: Remove signing key if: always() + shell: bash run: rm -f net/DevExtreme.AspNet.Data/release.snk - uses: actions/upload-artifact@v4 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 953fdb0a2..9869c7ef9 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -59,10 +59,11 @@ jobs: release-key-secret: ${{ secrets.RELEASE_KEY_SECRET }} - name: Pack NuGet package - run: dotnet pack net/DevExtreme.AspNet.Data -c "$BUILD_CONFIGURATION" --include-symbols + run: dotnet pack net/DevExtreme.AspNet.Data -c ${{ env.BUILD_CONFIGURATION }} --include-symbols - name: Remove signing key if: always() + shell: bash run: rm -f net/DevExtreme.AspNet.Data/release.snk - name: Upload npm packages as artifacts From 06c7caa75bd4ca8fb9cfac60dc5ce6930c0fd14d Mon Sep 17 00:00:00 2001 From: Mikhail Preyskurantov <5574159+mpreyskurantov@users.noreply.github.com> Date: Wed, 7 Oct 2026 21:46:53 +0300 Subject: [PATCH 6/6] permissions: workflow vs job --- .github/workflows/ci.yml | 13 +++++++++++-- .github/workflows/publish.yml | 5 +++-- 2 files changed, 14 insertions(+), 4 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 69fb70ed7..5335035f1 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -4,8 +4,7 @@ concurrency: group: ${{github.workflow}}-${{github.event.pull_request.number || github.sha}} cancel-in-progress: true -permissions: - contents: read +permissions: {} on: push: @@ -27,6 +26,8 @@ jobs: lint: runs-on: ubuntu-latest + permissions: + contents: read steps: - run: git config --global core.autocrlf true @@ -43,6 +44,8 @@ jobs: test-js: runs-on: ubuntu-latest + permissions: + contents: read strategy: fail-fast: false @@ -79,6 +82,8 @@ jobs: test-dotnet: runs-on: windows-latest + permissions: + contents: read steps: - uses: actions/checkout@v4 @@ -95,6 +100,8 @@ jobs: release-packages: runs-on: ubuntu-latest + permissions: + contents: read env: DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1 @@ -135,6 +142,8 @@ jobs: docfx: runs-on: windows-latest + permissions: + contents: read steps: - uses: actions/checkout@v4 diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 9869c7ef9..1c0fcbcbb 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -12,8 +12,7 @@ concurrency: group: ${{ github.workflow }}-${{ github.ref }} cancel-in-progress: false -permissions: - contents: read +permissions: {} env: NPM_CONFIG_AUDIT: "false" @@ -27,6 +26,8 @@ jobs: if: github.repository == 'DevExpress/DevExtreme.AspNet.Data' && github.event_name == 'workflow_dispatch' && startsWith(github.ref, 'refs/tags/') runs-on: ubuntu-latest environment: nuget + permissions: + contents: read env: DOTNET_SYSTEM_GLOBALIZATION_INVARIANT: 1