fix(ci): grant callers the permissions their reusable workflows decla… #144
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| # SPDX-License-Identifier: MPL-2.0 | |
| name: BoJ Server Build Trigger | |
| on: | |
| push: | |
| branches: [main, master] | |
| workflow_dispatch: | |
| permissions: | |
| contents: read | |
| jobs: | |
| trigger-boj: | |
| runs-on: ubuntu-latest | |
| timeout-minutes: 15 | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@692973e3d937129bcbf40652eb9f2f61becf3332 # v4.1.7 | |
| - name: Trigger BoJ Server (Casket/ssg-mcp) | |
| # NOTE: boj-server.local is an mDNS name that cannot resolve from a | |
| # GitHub-hosted runner, so this request can only fail here; the | |
| # continue-on-error below hides that. Left as-is deliberately — | |
| # repairing the syntax is in scope, redesigning the trigger is not. | |
| run: | | |
| curl -X POST "http://boj-server.local:7700/cartridges/ssg-mcp/invoke" \ | |
| -H "Content-Type: application/json" \ | |
| -d "{\"repo\": \"${{ github.repository }}\", \"branch\": \"${{ github.ref_name }}\", \"engine\": \"casket\"}" | |
| continue-on-error: true | |
| - name: K9-SVC Validation | |
| run: | | |
| echo "K9-SVC validation" | |
| [ -d .machine_readable/contractiles ] && echo "Contractiles present" || echo "No contractiles" |