Merge 86f43ed3c7e3bb5d2cb852949f645c875e468568 into de96f4613b77ec03b5cf633e7c350c32bd3c5660

This commit is contained in:
Kylie Stradley 2025-08-06 10:01:35 -04:00 committed by GitHub
commit d2fd2c51b1
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -325,3 +325,10 @@ If you must preserve permissions, you can `tar` all of your files together befor
name: my-artifact name: my-artifact
path: my_files.tar path: my_files.tar
``` ```
# Recommended Permissions
The `actions/download-artifact` workflow relies on an internal authentication pattern and does not use the GITHUB_TOKEN, to reduce risk of over-privileged token, jobs that use `actions/download-artifact` should set permissions to none:
```yaml
perm