Skip to content

Commit 1e4232e

Browse files
Fix workflow permissions for publishing security assets to releases
1 parent 05dc4d0 commit 1e4232e

File tree

1 file changed

+3
-2
lines changed

1 file changed

+3
-2
lines changed

.github/workflows/release.yaml

+3-2
Original file line numberDiff line numberDiff line change
@@ -31,8 +31,8 @@ jobs:
3131
check:
3232
runs-on: ubuntu-latest
3333
permissions:
34-
contents: read
3534
packages: write
35+
contents: write # publish sbom to GH releases/tag assets
3636
steps:
3737
- name: Checkout repository
3838
uses: actions/checkout@v3
@@ -46,6 +46,7 @@ jobs:
4646
dir: .
4747
upload-sbom-release-assets: true
4848

49+
4950
# Build docker images
5051
build-images:
5152
runs-on: ubuntu-latest
@@ -108,7 +109,7 @@ jobs:
108109
scan-images:
109110
runs-on: ubuntu-latest
110111
permissions:
111-
contents: read
112+
contents: write # For publishing assets to releases
112113
packages: write
113114
needs: [check, build-images]
114115
if: >

0 commit comments

Comments
 (0)