ci: scope release workflow token to contents read

`read-all` grants far more than the release jobs use; they only need repo read for checkout and authenticate uploads via Azure secrets. Narrow `GITHUB_TOKEN` to `contents: read`.

Signed-off-by: Benoit Tigeot <benoit.tigeot@lifen.fr>
pull/32491/head
Benoit Tigeot 2 months ago
parent 8fae8dd4c0
commit fe7ad77aa1
No known key found for this signature in database
GPG Key ID: 8E6D4FC8AEBDA62C

@ -7,7 +7,8 @@ on:
branches: branches:
- main - main
permissions: read-all permissions:
contents: read
# Note the only differences between release and canary-release jobs are: # Note the only differences between release and canary-release jobs are:
# - only canary passes --overwrite flag # - only canary passes --overwrite flag

Loading…
Cancel
Save