Skip to content

Add top-level permissions to changelog-radar workflow#219

Merged
jpr5 merged 1 commit into
mainfrom
fix/add-top-level-permissions
May 15, 2026
Merged

Add top-level permissions to changelog-radar workflow#219
jpr5 merged 1 commit into
mainfrom
fix/add-top-level-permissions

Conversation

@jpr5
Copy link
Copy Markdown
Contributor

@jpr5 jpr5 commented May 15, 2026

Summary

  • Add permissions: contents: read at the top level of changelog-radar.yml
  • Without a top-level permissions block, the workflow inherits the repo's default token permissions (often write-all), violating least-privilege

Test plan

  • Verify the scheduled run still creates issues (job-level issues: write is preserved)

@jpr5 jpr5 merged commit cdc7d19 into main May 15, 2026
14 checks passed
@jpr5 jpr5 deleted the fix/add-top-level-permissions branch May 15, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant