sigstore / gh-action-sigstore-python

A GitHub Action for sigstore-python
https://github.com/marketplace/actions/gh-action-sigstore-python
Apache License 2.0
46 stars 11 forks source link

readme: Should the default example have "contents:write" ? #147

Open jku opened 3 months ago

jku commented 3 months ago

Now that the default is to upload release artifacts, I wonder if we should add contents: write to the main usage example in README?

woodruffw commented 3 months ago

Yeah, makes sense to me!

webknjaz commented 3 months ago

I'd also request that every permission listed has a code comment clearly stating what it's for.

woodruffw commented 3 months ago

No objection. I'll try and find some time to do this in the coming days, unless someone else wants to do it first 😉