Skip to content

Fix: [AEA-0000] - review permissions for tag release#1013

Merged
anthony-nhs merged 1 commit intomainfrom
fixy
Mar 18, 2026
Merged

Fix: [AEA-0000] - review permissions for tag release#1013
anthony-nhs merged 1 commit intomainfrom
fixy

Conversation

@anthony-nhs
Copy link
Contributor

Summary

  • Routine Change

Details

  • review permissions for tag release

Copilot AI review requested due to automatic review settings March 18, 2026 12:24
@github-actions
Copy link
Contributor

This PR is linked to a ticket in an NHS Digital JIRA Project. Here's a handy link to the ticket:

AEA-0000

Copy link

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR updates GitHub Actions workflows to grant explicit token permissions needed by the tag_release reusable workflow, aligning CI/PR runs with the permissions already used for release workflows.

Changes:

  • Add permissions (OIDC id-token: write and repo contents: write) to the tag_release job in the PR workflow.
  • Add the same permissions to the tag_release job in the main-branch CI workflow.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 3 comments.

File Description
.github/workflows/pull_request.yml Grants explicit permissions to the PR tag_release job when invoking the reusable tag-release workflow.
.github/workflows/ci.yml Grants explicit permissions to the main CI tag_release job when invoking the reusable tag-release workflow.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

You can also share your feedback on Copilot code review. Take the survey.

@@ -83,6 +83,9 @@ jobs:
if: github.event_name != 'merge_group'
needs: [get_config_values]
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@update_jira
Comment on lines +87 to +88
id-token: 'write'
contents: 'write'
@@ -33,6 +33,9 @@ jobs:
tag_release:
needs: [quality_checks, get_commit_id, get_config_values]
uses: NHSDigital/eps-common-workflows/.github/workflows/tag-release-devcontainer.yml@update_jira
@anthony-nhs anthony-nhs merged commit ac5ab85 into main Mar 18, 2026
16 checks passed
@anthony-nhs anthony-nhs deleted the fixy branch March 18, 2026 12:27
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants