Make Actions token permissions explicit

The automatic job token creates the desktop release, so the CD desktop job
asks for contents: write; the images job keeps contents: read and asks for
packages: write so the job token can stand in for the scoped registry PAT.
CI stays read-only. The registry token itself remains a write:package-only
PAT (verified login + pull).
This commit is contained in:
2026-09-22 23:30:37 -05:00
parent 8f9656ac0e
commit ed6178d12e
2 changed files with 16 additions and 2 deletions
+5
View File
@@ -6,6 +6,11 @@
name: CI
# Tests and builds only need to read the repository; the automatic job token
# stays read-only.
permissions:
contents: read
on:
push:
branches: ["**"]