ci: explicit permissions for github app token (#1132)

This commit is contained in:
awwpotato 2025-04-13 03:40:57 -07:00 committed by GitHub
parent ce45f19e8a
commit 379ba613a6
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 4 additions and 0 deletions

View file

@ -31,6 +31,8 @@ jobs:
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write
- uses: actions/checkout@v4
with:

View file

@ -24,6 +24,8 @@ jobs:
with:
app-id: ${{ vars.APP_ID }}
private-key: ${{ secrets.APP_PRIVATE_KEY }}
permission-contents: write
permission-pull-requests: write
- uses: DeterminateSystems/update-flake-lock@v24
with: