Skip to content

fix(ci): use valid repository-projects permission key - #2

Closed
prabu-openclaw wants to merge 3 commits into
mainfrom
fix/workflow-invalid-projects-permission
Closed

prabu-openclaw wants to merge 3 commits into
mainfrom
fix/workflow-invalid-projects-permission

Conversation

@prabu-openclaw

Copy link
Copy Markdown

Summary

Related issue or project item

Testing performed

Collaboration checklist

  • Added or updated tests
  • Updated documentation if needed
  • Added the appropriate labels
  • Checked the linked GitHub Project item
  • Requested review from the Partner Agents team when appropriate

The project-collaboration workflow declared 'projects: write', which is not
a valid GitHub Actions permission scope. The invalid key makes the whole
workflow file fail validation, so GitHub emitted a zero-job failed run on
every push - despite the workflow only declaring issues/pull_request
triggers. That is the red X that has been appearing on every push.

Replaces it with 'repository-projects: write', the real scope name.
@prabu-openclaw
prabu-openclaw requested a review from a team as a code owner August 15, 2026 01:08

prabu-openclaw commented Aug 15, 2026 •

Copy link
Copy Markdown
Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

Two problems made CodeQL fail on every run:

1. Missing 'actions: read'. On private repos the CodeQL action must read the
   workflow run via the Actions API; without it the job died with
   'Resource not accessible by integration'.

2. The language matrix was hardcoded to [javascript, python] regardless of
   what the repo actually contains, so CodeQL was told to analyse a language
   with no source and aborted with 'no source code seen during build'.
   The matrix is now trimmed to the languages this repo actually has.
Two changes, both aimed at private-repo Actions spend:

1. CodeQL 'on: push' had no branch filter, so every push to a PR branch ran
   CodeQL twice - once for the push event and again for pull_request. Push is
   now limited to the default branch; PRs still get full analysis. Roughly
   halves CodeQL minutes.

2. Where a pure-Python matrix fanned out across ubuntu + macos + windows for
   every Python version, the full version sweep now runs on Linux (1x billing)
   with a single macOS and single Windows canary on the newest version.
   Cross-platform signal is kept; macOS jobs (10x billing) drop from 5 to 1.

Co-authored-by: prabu-openclaw <abgodbout@gmail.com>
@scrimshawlife-ctrl scrimshawlife-ctrl mentioned this pull request Sep 4, 2026
7 tasks done
@scrimshawlife-ctrl

Copy link
Copy Markdown
Contributor

Closing: CI red; workflow permission fix superseded by later org CI/SDLC commits on main. Re-open only if repository-projects key still broken on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants