Add permissions and concurrency groups to all workflows

Set contents: read permissions on every workflow and add per-workflow
concurrency groups keyed on the git ref to deduplicate concurrent runs.
Release workflow keeps cancel-in-progress: false so a release build is
never canceled; job-level contents: write on attach-to-release is
preserved. Concurrency groups use hardcoded prefixes so reusable
workflows called from release.yml do not inherit the caller workflow
name and collide.
This commit is contained in:
Bartosz Taudul
2026-08-09 12:27:22 +02:00
parent a8f9faf496
commit 37a7c2c197
10 changed files with 70 additions and 0 deletions

View File

@@ -8,6 +8,13 @@ on:
workflow_dispatch:
workflow_call:
permissions:
contents: read
concurrency:
group: linux-cli-${{ github.ref }}
cancel-in-progress: true
env:
CPM_SOURCE_CACHE: ${{ github.workspace }}/cpm-cache