Make Actions token permissions explicit
The automatic job token creates the desktop release, so the CD desktop job asks for contents: write; the images job keeps contents: read and asks for packages: write so the job token can stand in for the scoped registry PAT. CI stays read-only. The registry token itself remains a write:package-only PAT (verified login + pull).
This commit is contained in:
@@ -6,6 +6,11 @@
|
||||
|
||||
name: CI
|
||||
|
||||
# Tests and builds only need to read the repository; the automatic job token
|
||||
# stays read-only.
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ["**"]
|
||||
|
||||
Reference in New Issue
Block a user