Files
krkn/.github
Paige PattonandClaude Sonnet 4.6 496e866d8b fix: add top-level read-all permissions to release workflow (#1366)
Scorecard Token-Permissions check (alert #4) flags release.yml for
missing top-level permissions, which means GITHUB_TOKEN defaults to
broad write access across all jobs. Adding permissions: read-all at
the top level enforces least privilege by default; the release job
already declares contents: write at job level for the permissions it
actually needs.

Signed-off-by: Paige Patton <prubenda@redhat.com>
Co-authored-by: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 11:34:54 -04:00
..
2025-10-06 16:03:13 -04:00