fix(ci): wrapper permission union + standards re-pin to bd0df9e (post-lockfile follow-up) - #673
Conversation
…lint) Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
At standards >= fcb8669 the governance/hypatia/mirror/scorecard reusables declare actions: read (hypatia adds security-events: write; scorecard adds id-token/security-events write). A reusable requesting more than its caller grants is a startup_failure — the third enforcement layer after the lockfile and the caller entries. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedUpdates CI wrapper permissions to satisfy reusable workflow requirements and bumps the standards re-pin to bd0df9e for lockfile-aware governance linting. No issues found.
OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
The lockfile PR merged before this branch's final commits. This carries the remainder: reusable wrappers granted the permission union their reusables demand at standards >= fcb8669 (actions: read; hypatia adds security-events: write; scorecard adds id-token + security-events: write — a reusable requesting more than its caller grants is a startup_failure), and the standards re-pin bumped to bd0df9e (lockfile-aware governance lint via standards#574).
🤖 Generated with Claude Code