ci: grant actions:write so bun cache save succeeds - #51
Merged
jnasbyupgrade merged 1 commit intoJul 29, 2026
Merged
Conversation
|
Important Review skippedAuto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
jnasbyupgrade
marked this pull request as ready for review
July 29, 2026 19:36
Both claude.yml and claude-code-review.yml run claude-code-action, which internally uses oven-sh/setup-bun with caching enabled. Cache writes require the GITHUB_TOKEN to have actions:write; with only actions:read (or none), the cache save step logs a harmless but noisy "Cache reservation failed: cache write denied: token has no writable scopes" warning on every run.
jnasbyupgrade
force-pushed
the
fix-actions-cache-perm
branch
from
July 29, 2026 19:40
b13c8ae to
5fda4f9
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
claude.ymlandclaude-code-review.ymlboth runanthropics/claude-code-action, which internally usesoven-sh/setup-bunwith caching enabled.GITHUB_TOKENto haveactions: write; with onlyactions: read(or none), every run logs a harmless but noisy warning:Cache reservation failed: cache write denied: token has no writable scopes.actions: writein both workflows' jobpermissions:blocks.Security note
actions: writeis coarse-grained — besides cache read/write it also allows cancelling/re-running workflow runs and deleting artifacts/logs, but grants no additional contents/PR/secrets access. Forclaude-code-review.yml(apull_request_targetworkflow already gated to the trustedjnasbyupgradefork owner), this is a modest increase to the existing prompt-injection blast radius described in that file's comments — it does not enable code execution or repo writes beyond what the workflow already has.Test plan
Claude Code/Claude Code Reviewno longer shows the cache warning.