security(ci): add least-privilege permissions block to e2e-wheel workflow

e2e-wheel.yml was the only workflow missing a top-level permissions: block
(added during cross-OS work after PR #624 hardened the rest), so it ran with
default broad GITHUB_TOKEN scopes -> OpenSSF Scorecard Token-Permissions = 0.
Add 'permissions: contents: read' to match the other 7 workflows. CHANGELOG
W24 entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
AIOSAI
2026-06-08 10:09:00 -07:00
co-authored by Claude Opus 4.8
parent c7055de5e2
commit dab8d29645
2 changed files with 18 additions and 0 deletions
+5
View File
@@ -23,6 +23,11 @@ on:
- "src/**"
workflow_dispatch:
# Least-privilege token (Scorecard Token-Permissions). This workflow only
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
permissions:
contents: read
jobs:
e2e-wheel:
name: e2e-wheel (${{ matrix.os }})