Skip to content

Commit 8a6b936

Browse files
committed
chore: tighten release.yml workflow permissions
1 parent 462f19e commit 8a6b936

1 file changed

Lines changed: 4 additions & 2 deletions

File tree

.github/workflows/release.yml

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,13 +11,15 @@ on:
1111
required: true
1212
type: string
1313

14-
permissions:
15-
contents: write
14+
# Deny all permissions by default; grant only what each job needs.
15+
permissions: {}
1616

1717
jobs:
1818
release:
1919
name: Create GitHub Release
2020
runs-on: ubuntu-latest
21+
permissions:
22+
contents: write # create/update the GitHub Release and read the tagged ref
2123
env:
2224
RELEASE_TAG: ${{ github.event_name == 'workflow_dispatch' && github.event.inputs.tag || github.ref_name }}
2325
steps:

0 commit comments

Comments
 (0)