From 01f6c8b23a80021f209d3edefd906d59a590d758 Mon Sep 17 00:00:00 2001 From: Dominique Date: Wed, 9 Apr 2025 18:52:56 -0400 Subject: [PATCH] breakage workflow: update permissions The final step of the breakage workflow (breakage/upload) fails when a pull request comes from a fork because GITHUB_TOKEN restricts permissions in that scenario. This PR always allows breakage/upload to run. --- .github/workflows/Breakage.yml | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/.github/workflows/Breakage.yml b/.github/workflows/Breakage.yml index 5a9d623d..d8d13f4a 100644 --- a/.github/workflows/Breakage.yml +++ b/.github/workflows/Breakage.yml @@ -1,6 +1,11 @@ # Ref: https://securitylab.github.com/research/github-actions-preventing-pwn-requests name: Breakage +# allow breakage/upload when a PR comes from a fork +permissions: + contents: write + pull-requests: write + # read-only repo token # no access to secrets on: