ci: restrict GITHUB_TOKEN permissions to least privilege

Add explicit permissions blocks to all workflows to limit the scope
of the GITHUB_TOKEN rather than relying on the broad default permissions.

- build.yml: contents: read (checkout + artifacts)
- check-offline-permissions.yml: contents: read
- unsigned-release.yml: contents: read
- create-release.yml: contents: write (create release + upload assets)
- crowdin.yml: contents: write + pull-requests: write (push translations, open PRs)

https://claude.ai/code/session_012jEe5WfLkonuFPNZ7q7fKc
This commit is contained in:
Claude
2026-03-27 10:38:39 +00:00
parent d7a2697eb0
commit dacb9cc9aa
5 changed files with 16 additions and 0 deletions
+3
View File
@@ -6,6 +6,9 @@ on:
push:
branches: [master]
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest
@@ -6,6 +6,9 @@ on:
push:
branches: [master]
permissions:
contents: read
jobs:
check-offline-permissions:
runs-on: ubuntu-latest
+3
View File
@@ -5,6 +5,9 @@ on:
tags:
- 'v*' # Push events to matching v*, i.e. v1.0, v20.15.10
permissions:
contents: write
jobs:
deploy:
runs-on: ubuntu-latest
+4
View File
@@ -4,6 +4,10 @@ on:
push:
branches: [ master ]
permissions:
contents: write
pull-requests: write
jobs:
synchronize-with-crowdin:
runs-on: ubuntu-latest
+3
View File
@@ -5,6 +5,9 @@ on:
tags:
- 'v*'
permissions:
contents: read
jobs:
build:
runs-on: ubuntu-latest