Skip to content

fix(ci): use valid repository-projects permission key - #38

Merged
scrimshawlife-ctrl merged 3 commits into
mainfrom
fix/workflow-invalid-projects-permission
Aug 21, 2026
Merged

scrimshawlife-ctrl merged 3 commits into
mainfrom
fix/workflow-invalid-projects-permission

Conversation

@prabu-openclaw

Copy link
Copy Markdown
Contributor

Summary

Describe the change and its purpose.

Checks

  • npm test passes
  • No placeholder was made to look operational
  • Brand, philosophy, and motion constraints remain intact

The project-collaboration workflow declared 'projects: write', which is not
a valid GitHub Actions permission scope. The invalid key makes the whole
workflow file fail validation, so GitHub emitted a zero-job failed run on
every push - despite the workflow only declaring issues/pull_request
triggers. That is the red X that has been appearing on every push.

Replaces it with 'repository-projects: write', the real scope name.
@prabu-openclaw
prabu-openclaw requested a review from a team as a code owner August 15, 2026 01:08

prabu-openclaw commented Aug 15, 2026 •

Copy link
Copy Markdown
Contributor Author

This stack of pull requests is managed by Graphite. Learn more about stacking.

Two problems made CodeQL fail on every run:

1. Missing 'actions: read'. On private repos the CodeQL action must read the
   workflow run via the Actions API; without it the job died with
   'Resource not accessible by integration'.

2. The language matrix was hardcoded to [javascript, python] regardless of
   what the repo actually contains, so CodeQL was told to analyse a language
   with no source and aborted with 'no source code seen during build'.
   The matrix is now trimmed to the languages this repo actually has.
Two changes, both aimed at private-repo Actions spend:

1. CodeQL 'on: push' had no branch filter, so every push to a PR branch ran
   CodeQL twice - once for the push event and again for pull_request. Push is
   now limited to the default branch; PRs still get full analysis. Roughly
   halves CodeQL minutes.

2. Where a pure-Python matrix fanned out across ubuntu + macos + windows for
   every Python version, the full version sweep now runs on Linux (1x billing)
   with a single macOS and single Windows canary on the newest version.
   Cross-platform signal is kept; macOS jobs (10x billing) drop from 5 to 1.

Co-authored-by: prabu-openclaw <abgodbout@gmail.com>

@scrimshawlife-ctrl scrimshawlife-ctrl left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Approve. projects is not a valid GITHUB_TOKEN permission key; repository-projects is. CodeQL actions: read + push limited to main is correct. Python already dropped from the CodeQL matrix on main; remaining unique fix is the workflow permission key. Stacked #39 already merged.

@scrimshawlife-ctrl
scrimshawlife-ctrl merged commit 737882a into main Aug 21, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants