The job only reads commit messages, which works with the pull_request
trigger for PRs from forks too. Running it on both triggers checked every
PR twice, once with a privileged token it does not need.
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
Add an explicit permissions block to every workflow that relied on the
repository default. Entry points that only call reusable workflows get
permissions: {} and grant each call what the called workflow needs:
contents: read for the bundle and docker builds, contents: write for the
release, nothing for the admin-console dispatch (it uses its own token).
Workflows that check out code get contents: read; the commit checker
also gets pull-requests: read to list the PR commits.
Signed-off-by: David Barragán Merino <david.barragan@kaleidos.net>
* 📚 Add `:arrow_down:` emoji to the contributing guide
For cases where we need to downgrade dependencies
* ✨ Downgrade S3 SDK version
Mainly for minio and other S3-compatible services