[No QA] ci: Fix HTTP 403 on gh release create by granting contents:write permission#86795
Merged
MarioExpensify merged 1 commit intomainfrom Apr 2, 2026
Merged
Conversation
The createRelease job uses the default GITHUB_TOKEN to create and upload releases, which requires contents:write. Without an explicit permissions block, GitHub falls back to the repo default which is read-only, causing the 403 error. Made-with: Cursor
|
@MarioExpensify Please copy/paste the Reviewer Checklist from here into a new comment on this PR and complete it. If you have the K2 extension, you can simply click: [this button] |
Contributor
Reviewer Checklist
Screenshots/VideosAndroid: HybridAppAndroid: mWeb ChromeiOS: HybridAppiOS: mWeb SafariMacOS: Chrome / Safari |
MarioExpensify
approved these changes
Apr 2, 2026
Contributor
|
I understand we'll need to observe the next deploy to be sure this does not cause any issue, so let's keep an eye. |
Contributor
|
✋ This PR was not deployed to staging yet because QA is ongoing. It will be automatically deployed to staging after the next production release. |
Contributor
|
🚀 Deployed to staging by https://github.com/MarioExpensify in version: 9.3.52-0 🚀
Bundle Size Analysis (Sentry): |
Contributor
|
🚀 Deployed to production by https://github.com/roryabraham in version: 9.3.52-9 🚀
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Explanation of Change
The
createReleasejob usesGITHUB_TOKEN: ${{ github.token }}to rungh release createandgh release upload. Creating/uploading releases requirescontents: writepermission, but without an explicitpermissionsblock, GitHub falls back to the repository's default token permissions (which default to read-only). This causes a consistentHTTP 403: Resource not accessible by integrationerror.The fix adds
permissions: contents: writescoped to thecreateReleasejob only — the minimal least-privilege change needed. No other jobs are affected.It's unclear why this would've only just started being an issue.
Fixed Issues
$
PROPOSAL:
Tests
This is a CI/CD workflow change. The fix can be validated by observing the next staging or production deploy run successfully completing the
createReleasejob without a 403 error.Offline tests
N/A — CI workflow change.
QA Steps
N/A — CI workflow change, no user-facing behavior.
PR Author Checklist
### Fixed Issuessection aboveTestssectionOffline stepssectionQA stepssectioncanBeMissingparam foruseOnyxtoggleReportand notonIconClick)src/languages/*files and using the translation methodSTYLE.md) were followedAvatar, I verified the components usingAvatarare working as expected)StyleUtils.getBackgroundAndBorderStyle(theme.componentBG))npm run compress-svg)Avataris modified, I verified thatAvataris working as expected in all cases)Designlabel and/or tagged@Expensify/designso the design team can review the changes.ScrollViewcomponent to make it scrollable when more elements are added to the page.mainbranch was merged into this PR after a review, I tested again and verified the outcome was still expected according to theTeststeps.Screenshots/Videos
Android: Native
N/A
Android: mWeb Chrome
N/A
iOS: Native
N/A
iOS: mWeb Safari
N/A
MacOS: Chrome / Safari
N/A
Made with Cursor