security(ci): add least-privilege permissions block to e2e-wheel workflow
e2e-wheel.yml was the only workflow missing a top-level permissions: block (added during cross-OS work after PR #624 hardened the rest), so it ran with default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0. Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG W24 entry. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.8
parent
c7055de5e2
commit
dab8d29645
@@ -23,6 +23,11 @@ on:
|
||||
- "src/**"
|
||||
workflow_dispatch:
|
||||
|
||||
# Least-privilege token (Scorecard Token-Permissions). This workflow only
|
||||
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
e2e-wheel:
|
||||
name: e2e-wheel (${{ matrix.os }})
|
||||
|
||||
Reference in New Issue
Block a user