Skip to content

Give the release workflow permission to create GitHub releases - #2916

Merged
pvcraven merged 1 commit into
developmentfrom
fix/release-workflow-permissions
Oct 5, 2026
Merged

pvcraven merged 1 commit into
developmentfrom
fix/release-workflow-permissions

Conversation

@pvcraven

@pvcraven pvcraven commented Oct 5, 2026

Copy link
Copy Markdown
Member

Problem

The release workflow (.github/workflows/release.yml) never runs all the way through. Its last step, Publish GitHub Release (ncipollo/release-action), creates a GitHub release with the generated release notes. That needs contents: write, but the job only had contents: read, so the step fails with:

Error 403: Resource not accessible by integration - https://docs.github.com/rest/releases/releases#create-a-release

Every release run in the Actions history since 4.0.0.dev5 failed this way, including dev6, dev7 and dev8; the latest is run 37360674136. Every earlier step succeeded each time: build, publish to PyPI, and generate release notes. So the packages were published, but no GitHub release or notes were posted.

Fix

Change contents: read to contents: write for the release job, which is the permission needed to create a release. id-token: write, used for PyPI trusted publishing, is unchanged.

The release can only be fully checked by the next tag push.

🤖 Generated with Claude Code

The release workflow's "Publish GitHub Release" step (ncipollo/release-action)
creates a GitHub release with the generated notes, which needs
contents: write. The job only had contents: read, so the step failed with
"Error 403: Resource not accessible by integration" on every release
since 4.0.0.dev5. The earlier steps, including publishing to PyPI,
succeeded each time.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@pvcraven
pvcraven merged commit 9a205d8 into development Oct 5, 2026
10 of 12 checks passed
@pvcraven
pvcraven deleted the fix/release-workflow-permissions branch October 5, 2026 21:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant