Skip to content

Commit 55ac4d7

Browse files
committed
Flag defaultMode anywhere in a job that calls Claude
A settings file that an earlier step writes at run time can't be read by the step-level check, so also fail when the job's definition mentions defaultMode at all.
1 parent a83eb80 commit 55ac4d7

1 file changed

Lines changed: 6 additions & 0 deletions

File tree

‎.github/scripts/check_workflow_hardening.py‎

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -205,6 +205,12 @@ def check_job(file_name: str, job_id: str, job: dict) -> list[str]:
205205
f"Auto permission mode is not required for job '{job_id}' in {file_name}. "
206206
f"Reason: {EXEMPT_FROM_AUTO_MODE[key]}."
207207
)
208+
if "defaultMode" in json.dumps(job):
209+
# Catches a settings file that an earlier step of the job writes, which the
210+
# step-level check cannot read.
211+
errors.append(
212+
f"{where} mentions 'defaultMode': settings must not set a permission mode. {HELP}"
213+
)
208214
for index, step in enumerate(steps_of(job), start=1):
209215
if not runs_claude_code_action(step):
210216
continue

0 commit comments

Comments
 (0)