From fe7ad77aa1e1559c72e30c3cdc08b7eb0f27d4c6 Mon Sep 17 00:00:00 2001 From: Benoit Tigeot Date: Wed, 29 Jul 2026 17:24:24 +0200 Subject: [PATCH] ci: scope release workflow token to contents read `read-all` grants far more than the release jobs use; they only need repo read for checkout and authenticate uploads via Azure secrets. Narrow `GITHUB_TOKEN` to `contents: read`. Signed-off-by: Benoit Tigeot --- .github/workflows/release.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8f0a3429e..87b8caaa0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -7,7 +7,8 @@ on: branches: - main -permissions: read-all +permissions: + contents: read # Note the only differences between release and canary-release jobs are: # - only canary passes --overwrite flag