fix(ci): grant contents:write to the Gitea release job
The top-level `permissions: contents: read` added alongside the zizmor hardening applies to the release job too, and Gitea honours it: the built-in gitea-actions token became read-only, so `tea releases create` failed with "user should have a permission to write to a repo" (run 759). The .github workflow already narrowed write to its release job; the Gitea workflow has a single job and was left read-only. Grant it contents: write, keeping the read-only default at the top level.
This commit is contained in:
@@ -12,6 +12,8 @@ jobs:
|
|||||||
release:
|
release:
|
||||||
runs-on: cpu
|
runs-on: cpu
|
||||||
timeout-minutes: 20
|
timeout-minutes: 20
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
steps:
|
steps:
|
||||||
- name: Checkout
|
- name: Checkout
|
||||||
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
||||||
|
|||||||
Reference in New Issue
Block a user