Skip to content

ci: scope contents: write to release job only#9

Merged
kenvandine merged 2 commits into
lemonadefrom
copilot/fix-code-review-comment
Jun 1, 2026
Merged

ci: scope contents: write to release job only#9
kenvandine merged 2 commits into
lemonadefrom
copilot/fix-code-review-comment

Conversation

Copy link
Copy Markdown

Copilot AI commented Jun 1, 2026

With pull_request trigger enabled, the workflow-level contents: write permission applies to all jobs including compile jobs that run on PRs—unnecessarily broad for code that checks out and builds upstream dependencies.

Changes

  • Workflow-level permissions: Downgrade contents: writecontents: read (least-privilege default for all jobs)
  • release job: Add explicit permissions: contents: write scoped only to the job that creates tags and uploads release assets
# Before
permissions:
  contents: write   # applied to all jobs

# After
permissions:
  contents: read    # workflow default

jobs:
  release:
    permissions:
      contents: write   # only where needed

Copilot AI changed the title [WIP] Fix the code based on review comment ci: scope contents: write to release job only Jun 1, 2026
Copilot AI requested a review from kenvandine June 1, 2026 12:42
Copy link
Copy Markdown
Member

@kenvandine kenvandine left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Safer, thanks

@kenvandine kenvandine marked this pull request as ready for review June 1, 2026 12:42
@kenvandine kenvandine merged commit c00c8b8 into lemonade Jun 1, 2026
@kenvandine kenvandine deleted the copilot/fix-code-review-comment branch June 1, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants