Skip to content

Commit 2c42f3f

Browse files
andinuxclaude
andcommitted
ci: grant contents/issues write to changelog workflow call
The repo default GITHUB_TOKEN is read-only, so the reusable changelog workflow's requested permissions exceeded the caller's and every run failed at startup. Scope the grant to the calling job. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 1880ec8 commit 2c42f3f

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

‎.github/workflows/changelog.yml‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,6 +13,11 @@ on:
1313

1414
jobs:
1515
release:
16+
# Repo default is read-only; the called workflow needs write, and a reusable
17+
# workflow can never hold more than its caller.
18+
permissions:
19+
contents: write
20+
issues: write
1621
# Pin to a reviewed release tag (or, strongest, a full commit SHA) — not @main. See "Security" below.
1722
uses: sqlitecloud/changelog-action/.github/workflows/action.yml@v1
1823
with:

0 commit comments

Comments
 (0)