unsloth/.github
Daniel Han 053a4f3853 docker-publish: clean build-args + add least-privilege default permissions
- Move the explanatory prose out of the two `build-args:` blocks.
  docker/build-push-action forwards every non-empty line verbatim, so a
  leading-# line is passed as a bogus --build-arg; the comments now live above
  each block. This workflow has not run yet, so the issue was latent.
- Add a top-level `permissions: contents: read` default so every job (including
  smoke-test, which had none) limits the GITHUB_TOKEN. The merge jobs keep their
  own `packages: write` blocks. Addresses the CodeQL "workflow does not contain
  permissions" findings.
2026-06-26 05:41:51 +00:00
..
ISSUE_TEMPLATE Update issue template 2026-03-23 10:10:15 +05:30
scripts Add Local Agent Guides CI (#6547) 2026-06-22 04:21:48 -07:00
workflows docker-publish: clean build-args + add least-privilege default permissions 2026-06-26 05:41:51 +00:00
CODEOWNERS Update CODEOWNERS 2026-06-10 11:09:16 -07:00
dependabot.yml security: NOT affected by Mini Shai-Hulud (May-12 wave) -- forward-looking hardening only (#5397) 2026-05-13 04:58:12 -07:00
FUNDING.yml Update FUNDING.yml (#3792) 2025-12-28 19:57:43 -08:00