The top-level `permissions: contents: read` added alongside the zizmor hardening applies to the release job too, and Gitea honours it: the built-in gitea-actions token became read-only, so `tea releases create` failed with "user should have a permission to write to a repo" (run 759). The .github workflow already narrowed write to its release job; the Gitea workflow has a single job and was left read-only. Grant it contents: write, keeping the read-only default at the top level.