Skip to content

Conversation

@polyipseity
Copy link
Member

@polyipseity polyipseity commented Jan 25, 2026

  • Tighten permissions.
  • Add workflow_dispatch trigger for all workflows.

…ssions

- Add minimal file-level permissions (e.g. `contents: read`) to workflows
- Set `permissions: {}` on detect-quota jobs to avoid inheriting elevated permissions
- Update Docker CI to allow only `packages: write` and remove unnecessary `attestations/id-token` perms
- Keep elevated permissions scoped to the `release_please` job in release workflow
@polyipseity polyipseity merged commit 6b7943c into main Jan 25, 2026
13 checks passed
@polyipseity polyipseity deleted the chore/misc branch January 25, 2026 06:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants