fix(ci): grant contents:write to the Gitea release job
CI / build (push) Successful in 10s
CI / workflows (push) Successful in 9s
Release / release (push) Successful in 20s

The top-level `permissions: contents: read` added alongside the zizmor
hardening applies to the release job too, and Gitea honours it: the built-in
gitea-actions token became read-only, so `tea releases create` failed with
"user should have a permission to write to a repo" (run 759).

The .github workflow already narrowed write to its release job; the Gitea
workflow has a single job and was left read-only. Grant it contents: write,
keeping the read-only default at the top level.
This commit is contained in:
2026-07-21 15:23:29 -05:00
parent 250b3e98ca
commit 57e25f86f2
+2
View File
@@ -12,6 +12,8 @@ jobs:
release:
runs-on: cpu
timeout-minutes: 20
permissions:
contents: write
steps:
- name: Checkout
uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0