diff --git a/README.md b/README.md index b0f6224..deea09d 100644 --- a/README.md +++ b/README.md @@ -273,6 +273,9 @@ jobs: ```yaml on: push +# `contents:write` permission must be granted to the built-in token, see https://docs.github.com/en/actions/using-jobs/assigning-permissions-to-jobs +permissions: + contents: write #Require jobs: build: runs-on: ubuntu-latest @@ -311,8 +314,17 @@ jobs: git commit -m "generated" git push ``` + *NOTE:* The user email is `{user.id}+{user.login}@users.noreply.github.com`. See users API: https://api.github.com/users/github-actions%5Bbot%5D +# Recommended permissions + +When using the `checkout` action in your GitHub Actions workflow, it is recommended to set the following `GITHUB_TOKEN` permissions to ensure proper functionality, unless alternative auth is provided via the `token` or `ssh-key` inputs: + +```yaml +permissions: + contents: read +``` # License