Skip to content

fix: move contents:write to job-level in release workflow#152

Merged
cuioss-oliver merged 1 commit intomainfrom
fix/release-caller-permissions
Feb 4, 2026
Merged

fix: move contents:write to job-level in release workflow#152
cuioss-oliver merged 1 commit intomainfrom
fix/release-caller-permissions

Conversation

@cuioss-oliver
Copy link
Collaborator

Summary

  • Move contents: write from top-level to job-level in release.yml
  • Follows OpenSSF Scorecard recommendation for least-privilege token permissions
  • Resolves TokenPermissionsID alert on release.yml

Safe because the reusable release workflow uses a GitHub App token for all write operations.

Move the contents: write permission from top-level to job-level per
OpenSSF Scorecard recommendation for least-privilege token permissions.

Co-Authored-By: Claude Opus 4.5 <[email protected]>
@cuioss-oliver cuioss-oliver merged commit ba6ee3d into main Feb 4, 2026
7 checks passed
@cuioss-oliver cuioss-oliver deleted the fix/release-caller-permissions branch February 4, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant