From 4c41549a2fc187a50317e10c18605a733d329578 Mon Sep 17 00:00:00 2001 From: blckmn Date: Wed, 15 Jul 2026 13:31:27 +1000 Subject: [PATCH] Add explicit permissions blocks for read-default GITHUB_TOKEN The org default GITHUB_TOKEN permission is now read. Adds explicit permissions blocks so these keep the write access they rely on: stale.yaml (label/close issues and PRs) and build-release.yml (upload release assets, scoped to the release job). --- .github/workflows/build-release.yml | 2 ++ .github/workflows/stale.yaml | 4 ++++ 2 files changed, 6 insertions(+) diff --git a/.github/workflows/build-release.yml b/.github/workflows/build-release.yml index 7d7fe79d..0f235bcf 100644 --- a/.github/workflows/build-release.yml +++ b/.github/workflows/build-release.yml @@ -12,6 +12,8 @@ jobs: release_build: true release: + permissions: + contents: write name: Release needs: ci runs-on: ubuntu-22.04 diff --git a/.github/workflows/stale.yaml b/.github/workflows/stale.yaml index 74c4c2cd..4f9f6231 100644 --- a/.github/workflows/stale.yaml +++ b/.github/workflows/stale.yaml @@ -4,6 +4,10 @@ on: schedule: - cron: "30 4 * * *" +permissions: + issues: write + pull-requests: write + jobs: stale: name: 'Check and close stale issues'