Summary
Document the minimum required GitHub token permissions for using this action.
Background
From the security threat model (T5: Token Exposure), users should understand exactly what permissions are needed to reduce blast radius if credentials are compromised.
Acceptance Criteria
Priority
High - Security documentation
Related
- SECURITY.md threat model (T5)
Summary
Document the minimum required GitHub token permissions for using this action.
Background
From the security threat model (T5: Token Exposure), users should understand exactly what permissions are needed to reduce blast radius if credentials are compromised.
Acceptance Criteria
permissionsblockcontents: write- Create branches and commitspull-requests: write- Create pull requestsissues: write- Add labels to PRs (optional)GITHUB_TOKENwhere possiblePriority
High - Security documentation
Related