Skip to content

fix: grant reusable callers required permissions - #29

Merged
vitormattos merged 1 commit into
mainfrom
fix/reusable-caller-permissions
Sep 20, 2026
Merged

vitormattos merged 1 commit into
mainfrom
fix/reusable-caller-permissions

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Fix the npm-build reusable caller permission boundary.

The reusable workflow's change-detection job requires pull-requests: read. Reusable workflows cannot elevate GITHUB_TOKEN permissions beyond those granted by the caller, so a caller granting only contents: read can fail during workflow startup before any jobs are created.

This adds pull-requests: read to the generated npm-build caller.

The same rule is being applied to the ESLint caller before #28 is merged.

@vitormattos
vitormattos merged commit 46d3a66 into main Sep 20, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant