From 81cb345e36552ea211686c8912b2fa2ddb14b7a3 Mon Sep 17 00:00:00 2001 From: rory Date: Mon, 21 Sep 2026 22:33:35 -0700 Subject: [PATCH] Set cache-mode: read on reusable workflow calls from low-trust triggers actionlint flags a reusable workflow call triggered by pull_request_target, issue_comment, or issues that sets no cache-mode, because the callee can then request cache writes despite the trigger's read-only default. These workflows only read the cache, so cap them at read. This key is only recognised by the actionlint fork pinned in Expensify/GitHub-Actions, so the current check reports it as an unexpected key until that bump lands. Merge this right after that PR. --- .github/workflows/cla.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/cla.yml b/.github/workflows/cla.yml index dc4de9e..57a9a5e 100644 --- a/.github/workflows/cla.yml +++ b/.github/workflows/cla.yml @@ -8,5 +8,6 @@ on: jobs: CLA: + cache-mode: read uses: Expensify/GitHub-Actions/.github/workflows/cla.yml@main secrets: inherit