Skip to content

Commit e786964

Browse files
authored
Authorize shared PR security-review workflow to publish findings (#29052)
The goal is to make ruff/ty CI call the new shared PR security review workflow. To do that, the workflow needs permission to get a token from STS to publish comments on the PR. And that policy must be on main before the PR to integrate the call to the workflow can be tested. The PR to integrate the call to the workflow will follow.
1 parent a81291e commit e786964

1 file changed

Lines changed: 10 additions & 0 deletions

File tree

‎.github/secure-token-service.json‎

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -30,6 +30,16 @@
3030
"permissions": { "contents": "write", "pull_requests": "write" },
3131
"target": "ruff"
3232
},
33+
{
34+
"caller": "ruff",
35+
"environment": "automations",
36+
"caller_ref": "refs/pull/*/merge",
37+
"caller_workflow": "ci.yaml",
38+
"reusable_workflow": "astral-sh/github-actions/.github/workflows/pull-request-security-review.yml@45c506043c254690f2612686e5d5a72c81c251a4",
39+
"on": ["pull_request"],
40+
"permissions": { "pull_requests": "write" },
41+
"target": "ruff"
42+
},
3343
{
3444
"caller": "ruff",
3545
"environment": "release",

0 commit comments

Comments
 (0)