Add read permissions to `publish-crates` job (#16797)

This commit is contained in:
Zanie Blue 2025-11-20 16:38:19 -06:00 committed by GitHub
parent f2e92b4bfb
commit 8d8aabb884
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
2 changed files with 2 additions and 3 deletions

View File

@ -233,8 +233,7 @@ jobs:
secrets: inherit
# publish jobs get escalated permissions
permissions:
"id-token": "write"
"packages": "write"
"contents": "read"
# Create a GitHub Release while uploading all files to it
announce:

View File

@ -61,7 +61,7 @@ publish-jobs = ["./publish-pypi", "./publish-crates"]
# Post-announce jobs to run in CI
post-announce-jobs = ["./publish-docs"]
# Custom permissions for GitHub Jobs
github-custom-job-permissions = { "build-docker" = { packages = "write", contents = "read", id-token = "write", attestations = "write" } }
github-custom-job-permissions = { "build-docker" = { packages = "write", contents = "read", id-token = "write", attestations = "write" }, "publish-crates" = { contents = "read" } }
# Whether to install an updater program
install-updater = false
# Path that installers should place binaries in