Skip to content

fix(ci): wrapper permission union + standards re-pin to bd0df9e (post-lockfile follow-up) - #673

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/actions-lockfile
Aug 4, 2026
Merged

fix(ci): wrapper permission union + standards re-pin to bd0df9e (post-lockfile follow-up)#673
hyperpolymath merged 2 commits into
mainfrom
ci/actions-lockfile

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The lockfile PR merged before this branch's final commits. This carries the remainder: reusable wrappers granted the permission union their reusables demand at standards >= fcb8669 (actions: read; hypatia adds security-events: write; scorecard adds id-token + security-events: write — a reusable requesting more than its caller grants is a startup_failure), and the standards re-pin bumped to bd0df9e (lockfile-aware governance lint via standards#574).

🤖 Generated with Claude Code

hyperpolymath and others added 2 commits August 4, 2026 10:38
…lint)

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
At standards >= fcb8669 the governance/hypatia/mirror/scorecard
reusables declare actions: read (hypatia adds security-events: write;
scorecard adds id-token/security-events write). A reusable requesting
more than its caller grants is a startup_failure — the third
enforcement layer after the lockfile and the caller entries.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@gitar-bot

gitar-bot Bot commented Aug 4, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Updates CI wrapper permissions to satisfy reusable workflow requirements and bumps the standards re-pin to bd0df9e for lockfile-aware governance linting. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Important

Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot
gitar-bot Bot enabled auto-merge (squash) August 4, 2026 09:39

@gitar-bot gitar-bot Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-bot gitar-bot Bot added the gitar-approved Added by Gitar label Aug 4, 2026
@hyperpolymath
hyperpolymath merged commit 2ef7a77 into main Aug 4, 2026
28 of 34 checks passed
@hyperpolymath
hyperpolymath deleted the ci/actions-lockfile branch August 4, 2026 09:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approved Added by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant