Repository navigation
Fixup GHA token permission for releasing - #48
Conversation
There was a problem hiding this comment.
Pull request overview
Updates the “Test and Release” GitHub Actions workflow to allow the release job to write repository contents (needed for creating tags/releases) by adjusting the GITHUB_TOKEN permissions.
Changes:
- Add an explicit job-level
permissionsblock to thereleasejob. - Grant
contents: writefor thereleasejob.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| - build | ||
| runs-on: ubuntu-latest | ||
| permissions: | ||
| contents: write |
There was a problem hiding this comment.
Setting a job-level permissions block overrides the default token permissions for all scopes. Since this job uses actions/download-artifact, it typically needs actions: read to fetch artifacts; with only contents: write, the step can fail with 403. Consider explicitly adding actions: read (and any other required scopes) alongside contents: write so the release job can still download artifacts.
| contents: write | |
| contents: write | |
| actions: read |
There was a problem hiding this comment.
Pull request overview
Copilot reviewed 1 out of 1 changed files in this pull request and generated no new comments.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Hoping to fix this error: