Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
GitHub Actionsと GitHub CLIと permissions
Search
ゆきか
November 22, 2024
Technology
220
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
GitHub Actionsと GitHub CLIと permissions
ゆきか
November 22, 2024
More Decks by ゆきか
See All by ゆきか
新潟の鮨のはなし 飯テロver
yukikayuki
0
330
新潟WEBアプリケーション勉強会 Vol.1 LT GraphQL Federation
yukikayuki
0
150
React Hooks勉強会 vol.5
yukikayuki
2
390
Other Decks in Technology
See All in Technology
DORA_Metrics.pdf
wagnerfusca
1
110
AIに賢く動いてもらうためのコンテキスト〜Snowflake女子会 vol.8
snowwmn0824
0
180
特殊変数大全
dak2
0
150
PQC移行の今 -- IETF からみた現在地
satokan
4
480
AI臭い文章とは何なのか
nasuvitz
3
440
CI/CDではもう遅い - 人とAIが迂回しないDevSecOps Verify基盤の再設計 -
kintotechdev
1
330
Oracle Base Database Service 技術詳細
oracle4engineer
PRO
16
120k
「ピッケル本」日本語版は4.0(第6版)が出版されるべき / pickaxe4-nagoyark05
kakutani
2
310
Azure Serverless 2026:Production-ready な AI エージェント基盤 / Azure Serverless 2026: Production-Ready AI Agent Platform
miyake
2
630
「大丈夫そう?」をObservabilityで確かめる
mrmtsu
0
190
AIエージェントを安全で速い現場監督にする:Jev・Obsidian・メタハーネス
x5gtrn
PRO
0
130
Coil3を内部実装から読み解く~キャッシュ戦略とAVIF画像の描画〜/nikkei-tech-talk50
nikkei_engineer_recruiting
0
110
Featured
See All Featured
The AI Revolution Will Not Be Monopolized: How open-source beats economies of scale, even for LLMs
inesmontani
PRO
3
3.7k
Max Prin - Stacking Signals: How International SEO Comes Together (And Falls Apart)
techseoconnect
PRO
0
470
実際に使うSQLの書き方 徹底解説 / pgcon21j-tutorial
soudai
PRO
203
76k
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
350
Game over? The fight for quality and originality in the time of robots
wayneb77
1
290
Balancing Empowerment & Direction
lara
6
1.3k
Pawsitive SEO: Lessons from My Dog (and Many Mistakes) on Thriving as a Consultant in the Age of AI
davidcarrasco
0
250
[SF Ruby Conf 2025] Rails X
palkan
3
1.4k
Accessibility Awareness
sabderemane
1
220
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
310
Build The Right Thing And Hit Your Dates
maggiecrowley
39
3.5k
Prompt Engineering for Job Search
mfonobong
0
460
Transcript
GitHub Actionsと GitHub CLIと permissions 2024-11-22 Niigata 5Min Tech #14
@_yukikayuki
自己紹介 KANEDA Takayuki (@_yukikayuki) 株式会社モニクル ソフトウェアエンジニア(Web) + プロダクトSRE 最近メガネを変えた
GitHub ActionsでGitHub CLIを使いたいことあります か?
GitHub Actions(以降GHA)とは > GitHub Actions は、ビルド、テスト、デプロイのパイプラインを自動化でき る継続的インテグレーションと継続的デリバリー (CI/CD) のプラットフォームで す。
リポジトリに対するすべての pull request をビルドしてテストしたり、 マージされた pull request を運用環境にデプロイしたりするワークフローを 作成できます。
利用例 プルリクオープン時のテスト・リント・プレビュー環境へのデプロイ mainブランチへマージした時の本番デプロイ プレビュー環境のクリーニングの定期実行
GitHub CLI(以降ghコマンド)とは > GitHub CLI は、コンピューターのコマンド ラインから GitHub を使用する ためのオープン
ソース ツールです。 コマンドラインから作業しているときは、 GitHub CLI を使用して時間を節約し、コンテキストの切り替えを回避できま す。 できること: Issue と pull request の作成、クローズ、編集、一覧表示、プル リクエストのレビュー、diff、マージなどなど
利用例 リポジトリをクローンする Twitter(現X)で見かけたが、若い人はghコマンドでリポジトリをクローンし ている? ローカルマシンからプルリクを作る gh pr create --title "The
bug is fixed" --body "Everything works again" GHAでリポジトリの情報を取得して何かゴニョゴニョする
GHAでghコマンドを使うには?
jobs: info: runs-on: ubuntu-latest permissions: contents: read pull-requests: read steps:
- uses: actions/checkout@v4 - name: is pr closed shell: bash env: GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | pr_number=${{ github.event.pull_request.number }} is_pr_closed=$(gh pr view $pr_number --json closed -q '.closed') echo $is_pr_closed # false
jobs: info: runs-on: ubuntu-latest permissions: # permissionを指定 contents: read pull-requests:
read steps: - uses: actions/checkout@v4 - name: is pr closed shell: bash env: # 以下の形でGH_TOKENを設定 GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: | pr_number=${{ github.event.pull_request.number }} is_pr_closed=$( gh pr view $pr_number --json closed -q '.closed' ) echo $is_pr_closed # false
permission > 優れたセキュリティ プラクティスとし て、GITHUB_TOKEN に必要最小限の アクセス権を付与することをお勧めしま す。 permissions: actions:
read|write|none attestations: read|write|none checks: read|write|none contents: read|write|none deployments: read|write|none id-token: write|none issues: read|write|none discussions: read|write|none packages: read|write|none pages: read|write|none pull-requests: read|write|none repository-projects: read|write|none security-events: read|write|none statuses: read|write|none
参考URL • https://docs.github.com/ja/actions/about-github-actions/und erstanding-github-actions • https://docs.github.com/ja/github-cli/github-cli/about-github -cli • https://docs.github.com/ja/enterprise-cloud@latest/actions/ writing-workflows/choosing-what-your-workflow-does/contr
olling-permissions-for-github_token