Skip to content

Commit 339cef8

Browse files
committed
fix: add explicit permissions to release workflow
Adds 'permissions: contents: read' to limit GITHUB_TOKEN permissions following security best practices. The workflow uses a GitHub App token for privileged operations, so limiting the default token to read-only is appropriate.
1 parent 5e47e39 commit 339cef8

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

.github/workflows/release.yml

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,8 @@
11
name: Release
22

3+
permissions:
4+
contents: read
5+
36
on:
47
workflow_dispatch:
58
inputs:

0 commit comments

Comments
 (0)