ci(publish): security update at publish.yml #10
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
Restrict 'packages: write' permission to publish job in publish.yml
Set top-level permissions to 'contents: read' to follow the principle of least privilege.
Scoped 'packages: write' permission to the 'publish' job to reduce security risks.
Align workflow with GitHub's recommended security best practices.
Related Issue: Closes [Security] - Restrict 'packages: write' Permission to Specific Job in publish.yml Workflow #9
Type of Change:
Checklist
Please ensure the following guidelines are met:
type(scope): description
.Additional Information
Please provide any additional information or context here. If applicable, add screenshots to help explain the changes.