From bc142a25ffa90be1ef6b6c91c5b1cc9dd7c315a8 Mon Sep 17 00:00:00 2001 From: Jo <10510431+j178@users.noreply.github.com> Date: Sat, 31 Jan 2026 21:13:38 +0800 Subject: [PATCH] Fix permission for docker attestation (#1511) --- .github/workflows/build-docker.yml | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build-docker.yml b/.github/workflows/build-docker.yml index 39414c89..35ccb0cf 100644 --- a/.github/workflows/build-docker.yml +++ b/.github/workflows/build-docker.yml @@ -21,8 +21,6 @@ env: permissions: contents: read - # TODO(zanieb): Ideally, this would be `read` on dry-run but that will require - # significant changes to the workflow. packages: write # zizmor: ignore[excessive-permissions] jobs: @@ -116,6 +114,11 @@ jobs: name: release needs: - docker-build + permissions: + contents: read + packages: write + id-token: write + attestations: write if: ${{ inputs.plan != '' && !fromJson(inputs.plan).announcement_tag_is_implicit }} steps: - name: Download digests