Skip to content

Commit bd6409b

Browse files
committed
remove contents: write permission and add back explanatory comments that were lost
1 parent 2304a9b commit bd6409b

File tree

1 file changed

+6
-8
lines changed

1 file changed

+6
-8
lines changed

.github/workflows/release-please.yml

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,8 @@ jobs:
3535
release-please:
3636
runs-on: ubuntu-latest
3737
permissions:
38-
contents: write
39-
pull-requests: write
38+
contents: write # Needed for release-please to create releases.
39+
pull-requests: write # Needed for release-please to create/update PRs.
4040
if: github.event_name == 'push'
4141
outputs:
4242
package-server-ai-released: ${{ steps.release.outputs['packages/sdk/server-ai--release_created'] }}
@@ -49,8 +49,7 @@ jobs:
4949
runs-on: ubuntu-latest
5050
needs: ['release-please']
5151
permissions:
52-
id-token: write
53-
contents: write
52+
id-token: write # Needed for OIDC to get release secrets from AWS.
5453
if: ${{ needs.release-please.outputs.package-server-ai-released == 'true' }}
5554
steps:
5655
- uses: actions/checkout@v4
@@ -89,8 +88,7 @@ jobs:
8988
runs-on: ubuntu-latest
9089
needs: ['release-please']
9190
permissions:
92-
id-token: write
93-
contents: write
91+
id-token: write # Needed for OIDC to get release secrets from AWS.
9492
if: ${{ always() && !failure() && !cancelled() && needs.release-please.outputs.package-server-ai-langchain-released == 'true' }}
9593
steps:
9694
- uses: actions/checkout@v4
@@ -129,8 +127,8 @@ jobs:
129127
runs-on: ubuntu-latest
130128
if: github.event_name == 'workflow_dispatch'
131129
permissions:
132-
id-token: write
133-
contents: read
130+
id-token: write # Needed for OIDC to get release secrets from AWS.
131+
contents: read # Needed for actions/checkout.
134132
steps:
135133
- uses: actions/checkout@v4
136134

0 commit comments

Comments
 (0)