fix(ci): grant scorecard caller the reusable's job-level permissions - #343
Conversation
scorecard-reusable's job (not just its workflow header) requests security-events: write and id-token: write; caller-side permission validation applies at job level too, so OSSF Scorecard remained startup_failure after #342 fixed the workflow-level grants. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedGrants the scorecard caller the reusable's job-level permissions to fix startup failures. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
Completes #342: scorecard-reusable's job requests
security-events: write+id-token: writebeyond the workflow-levelactions: read/contents: read; caller grants must cover job-level requests too, so OSSF Scorecard was the one re-pinned caller still dying at startup. One file, four permission lines.🤖 Generated with Claude Code