fix: add missing permissions to build-changelog-scrubber-lambda job#3446
Conversation
Mirrors the contents: read permission already present on build-link-index-lambda.
Without it the top-level permissions: {} causes the reusable workflow's nested
job to inherit contents: none, failing validation.
Co-Authored-By: Claude Sonnet 4.6 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 57 minutes and 55 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Enterprise Run ID: 📒 Files selected for processing (1)
✨ Finishing Touches✨ Simplify code
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Why
The release workflow sets
permissions: {}at the top level, which zeros out all token permissions. Thebuild-changelog-scrubber-lambdajob was missing its ownpermissionsblock, so the reusable workflow's nested job could only inheritcontents: none— causing a validation error that blocked the entire release run.What
Added
permissions: contents: readtobuild-changelog-scrubber-lambdainrelease.yml, mirroring the identical block already present onbuild-link-index-lambda(added in #3444).