Skip to content

Commit 05ce0a2

Browse files
committed
Add permissions
1 parent dede7fa commit 05ce0a2

3 files changed

Lines changed: 8 additions & 3 deletions

File tree

.github/workflows/build.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ jobs:
1818
platform: [ubuntu-latest, macos-latest, windows-latest]
1919
runs-on: ${{ matrix.platform }}
2020
permissions:
21-
contents: read
21+
contents: write
2222
security-events: write
2323

2424
steps:
@@ -107,6 +107,7 @@ jobs:
107107
build/dfetch-package/*.msi
108108
build/dfetch-package/*.cdx.json
109109
overwrite_files: false
110+
draft: true
110111
env:
111112
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
112113

.github/workflows/ci.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
needs: draft-release
2828
uses: ./.github/workflows/build.yml
2929
permissions:
30-
contents: read
30+
contents: write
3131
security-events: write
3232
with:
3333
release_id: ${{ needs.draft-release.outputs.release_id }}
@@ -45,7 +45,7 @@ jobs:
4545
needs: draft-release
4646
uses: ./.github/workflows/python-publish.yml
4747
permissions:
48-
contents: read
48+
contents: write
4949
security-events: write
5050
id-token: write
5151
with:

.github/workflows/python-publish.yml

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -99,6 +99,9 @@ jobs:
9999
runs-on: ubuntu-latest
100100
if: ${{ inputs.release_id }}
101101
needs: build
102+
permissions:
103+
contents: write
104+
security-events: write
102105
steps:
103106
- name: Download all the dists
104107
uses: actions/download-artifact@37930b1c2abaa49bbe596cd826c3c89aef350131 # v5
@@ -111,5 +114,6 @@ jobs:
111114
tag_name: ${{ inputs.release_id }}
112115
files: dist/*
113116
overwrite_files: false
117+
draft: true
114118
env:
115119
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}

0 commit comments

Comments
 (0)