File tree Expand file tree Collapse file tree 2 files changed +15
-3
lines changed Expand file tree Collapse file tree 2 files changed +15
-3
lines changed Original file line number Diff line number Diff line change 1+ # CODEOWNERS - Require review from maintainers for critical files
2+ /.github /workflows / @ abubnalitic-nbl @ ltucker
3+ /pyproject.toml @ abubnalitic-nbl @ ltucker
4+ /.github /CODEOWNERS @ abubnalitic-nbl @ ltucker
Original file line number Diff line number Diff line change 11name : Release
22
3+ # Global defaults - read-only (least privilege)
34permissions :
4- contents : write
5- issues : write
6- pull-requests : write
5+ contents : read
6+ issues : read
7+ pull-requests : read
78
89on :
910 workflow_dispatch :
1011
1112jobs :
1213 release :
1314 runs-on : ubuntu-latest
15+ environment : release # Requires manual approval in GitHub settings
16+
17+ # Job-specific write permissions (least privilege)
18+ permissions :
19+ contents : write # Push tags and CHANGELOG
20+ issues : write # Create release issues
21+ pull-requests : write # Create release PRs
1422
1523 steps :
1624 - uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
You can’t perform that action at this time.
0 commit comments