Skip to content

ci: grant job-metadata read access to the isolated status publisher - #10

Merged
coisa merged 2 commits into
mainfrom
codex/ci-publisher-actions-read
Oct 8, 2026
Merged

coisa merged 2 commits into
mainfrom
codex/ci-publisher-actions-read

Conversation

@coisa

@coisa coisa commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

The isolated per-version publisher introduced by DevTools #362 needs actions: read in the caller's permission ceiling. GitHub validates this ceiling even when publication is disabled, so the current caller would fail before starting its jobs after adopting that workflow.

This grants read access to workflow job metadata. The shared workflow keeps test execution jobs at contents: read, actions: none and statuses: none; it reserves status writes for the separate publisher.

Validation: actionlint .github/workflows/tests.yml and git diff --check passed. A controlled GitHub caller with the old ceiling failed before creating jobs (negative case); changing only Actions read permission made the same pinned reusable workflow succeed (control). Library code, Dash artwork and README content are untouched. Merge this caller compatibility update before DevTools #362.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-10-07T23:34:50.611404Z afff8e2 PR opened
🔒 Security Review ✅ Completed 2026-10-07T23:35:22.886441Z afff8e2 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@coderabbitai

coderabbitai Bot commented Oct 7, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: 42861cc0-227d-4f78-bbbc-8220ca6c618a
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coisa
coisa merged commit f7d85af into main Oct 8, 2026
20 checks passed
@coisa
coisa deleted the codex/ci-publisher-actions-read branch October 8, 2026 19:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant