Skip to content

fix(ci): wrapper permission union + standards re-pin to bd0df9e (post-lockfile follow-up) - #103

Merged
hyperpolymath merged 2 commits into
mainfrom
ci/actions-lockfile
Aug 4, 2026
Merged

fix(ci): wrapper permission union + standards re-pin to bd0df9e (post-lockfile follow-up)#103
hyperpolymath merged 2 commits into
mainfrom
ci/actions-lockfile

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

The lockfile PR merged before this branch's final commits. This carries the remainder: reusable wrappers granted the permission union their reusables demand at standards >= fcb8669 (actions: read; hypatia adds security-events: write; scorecard adds id-token + security-events: write — a reusable requesting more than its caller grants is a startup_failure), and the standards re-pin bumped to bd0df9e (lockfile-aware governance lint via standards#574).

🤖 Generated with Claude Code

hyperpolymathand others added 2 commits August 4, 2026 10:38
…lint)
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
At standards >= fcb8669 the governance/hypatia/mirror/scorecard
reusables declare actions: read (hypatia adds security-events: write;
scorecard adds id-token/security-events write). A reusable requesting
more than its caller grants is a startup_failure — the third
enforcement layer after the lockfile and the caller entries.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@gitar-bot

gitar-botBot commented Aug 4, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review✅ Approved

Grants CI wrapper workflows the permission union required by their reusables and bumps the standards re-pin to commit bd0df9e. No issues found.

Auto-approved and auto-merge armed: No blocking issues found.
Please see Auto-approve Docs for details on setting custom approval criteria. — merges when pipeline and required approvals pass.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose 

Important

Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

@gitar-bot
gitar-botBot enabled auto-merge (squash) August 4, 2026 09:39

@gitar-botgitar-botBot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Gitar has auto-approved this PR and enabled auto-merge (configure)

@gitar-botgitar-botBot added the gitar-approved Added by Gitar label Aug 4, 2026
@hyperpolymath
hyperpolymath merged commit f0d8231 into mainAug 4, 2026
20 checks passed
@hyperpolymath
hyperpolymath deleted the ci/actions-lockfile branch August 4, 2026 09:51
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gitar-approvedAdded by Gitar

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@hyperpolymath