Przeglądaj źródła

ignore: tweak permissions

Aiden Cline 5 miesięcy temu
rodzic
commit
64617c113a

+ 3 - 3
.github/workflows/opencode.yml

@@ -13,10 +13,10 @@ jobs:
       startsWith(github.event.comment.body, '/opencode')
       startsWith(github.event.comment.body, '/opencode')
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     permissions:
     permissions:
-      contents: write
-      pull-requests: write
-      issues: write
       id-token: write
       id-token: write
+      contents: read
+      pull-requests: read
+      issues: read
     steps:
     steps:
       - name: Checkout repository
       - name: Checkout repository
         uses: actions/checkout@v4
         uses: actions/checkout@v4

+ 3 - 3
packages/opencode/src/cli/cmd/github.ts

@@ -334,10 +334,10 @@ jobs:
       startsWith(github.event.comment.body, '/opencode')
       startsWith(github.event.comment.body, '/opencode')
     runs-on: ubuntu-latest
     runs-on: ubuntu-latest
     permissions:
     permissions:
-      contents: write
-      pull-requests: write
-      issues: write
       id-token: write
       id-token: write
+      contents: read
+      pull-requests: read
+      issues: read
     steps:
     steps:
       - name: Checkout repository
       - name: Checkout repository
         uses: actions/checkout@v4
         uses: actions/checkout@v4