Skip to content

Commit 19d34ab

Browse files
authored
fix(ci): set caller-scope permissions for reusable review workflows (#30)
1 parent 826f4c2 commit 19d34ab

2 files changed

Lines changed: 6 additions & 10 deletions

File tree

.github/workflows/claude-review-manual.yml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -15,14 +15,12 @@ on:
1515

1616
permissions:
1717
contents: read
18+
pull-requests: write # zizmor: ignore[excessive-permissions] required for reusable review workflow
19+
issues: write # zizmor: ignore[excessive-permissions] required for reusable review workflow
20+
id-token: write # zizmor: ignore[excessive-permissions] required for Azure OIDC login
1821

1922
jobs:
2023
claude-review:
21-
permissions:
22-
contents: read
23-
pull-requests: write
24-
issues: write
25-
id-token: write
2624
uses: codingworkflow/codingworkflow-security-policies/.github/workflows/reusable-claude-review.yml@55070d1bc124fbe46d9a8edbc8d536826d4e15ed
2725
with:
2826
pr_number: ${{ inputs.pr_number }}

.github/workflows/opencode-review-manual.yml

Lines changed: 3 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -30,14 +30,12 @@ on:
3030

3131
permissions:
3232
contents: read
33+
pull-requests: write # zizmor: ignore[excessive-permissions] required for reusable review workflow
34+
issues: write # zizmor: ignore[excessive-permissions] required for reusable review workflow
35+
id-token: write # zizmor: ignore[excessive-permissions] required for Azure OIDC login
3336

3437
jobs:
3538
opencode-review:
36-
permissions:
37-
contents: read
38-
pull-requests: write
39-
issues: write
40-
id-token: write
4139
uses: codingworkflow/codingworkflow-security-policies/.github/workflows/reusable-opencode-review.yml@55070d1bc124fbe46d9a8edbc8d536826d4e15ed
4240
with:
4341
pr_number: ${{ inputs.pr_number }}

0 commit comments

Comments
 (0)