Skip to content

Commit 47ac00d

Browse files
hyperpolymathclaude
andcommitted
fix(ci): scope wiki-sync's contents: write to the job that pushes
Hypatia WH002 flagged the top-level `permissions: contents: write` on wiki-sync.yml. The top level is now `contents: read`, and the single `sync` job carries `contents: write`, because scripts/wiki-sync.sh does push to the wiki with GITHUB_TOKEN. Behaviour is unchanged; the grant is no longer inherited by any job added later. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01QYY8Gp4v4x2J7iSNn1vZ57
1 parent 826ef62 commit 47ac00d

1 file changed

Lines changed: 4 additions & 1 deletion

File tree

‎.github/workflows/wiki-sync.yml‎

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,7 +12,7 @@ on:
1212
workflow_dispatch:
1313

1414
permissions:
15-
contents: write
15+
contents: read
1616

1717
concurrency:
1818
group: wiki-sync
@@ -21,6 +21,9 @@ concurrency:
2121
jobs:
2222
sync:
2323
runs-on: ubuntu-latest
24+
# Write is scoped to this job only: scripts/wiki-sync.sh pushes to the wiki.
25+
permissions:
26+
contents: write
2427
timeout-minutes: 10
2528
steps:
2629
- uses: actions/checkout@v7.0.1

0 commit comments

Comments
 (0)