Skip to content

fix(ci): grant callers the permissions their reusable workflows decla… #76

fix(ci): grant callers the permissions their reusable workflows decla…

fix(ci): grant callers the permissions their reusable workflows decla… #76

Workflow file for this run

# This workflow is managed by gh actions-lock.
# SPDX-License-Identifier: MPL-2.0
# This workflow is managed by gh actions-lock.
# This workflow is managed by gh actions-lock.
# governance.yml — single wrapper calling the shared estate governance bundle
# in hyperpolymath/standards instead of carrying per-repo copies.
#
# Replaces the per-repo governance scaffolding removed in the same commit:
# quality.yml, guix-nix-policy.yml, npm-bun-blocker.yml, ts-blocker.yml,
# security-policy.yml, rsr-antipattern.yml, wellknown-enforcement.yml,
# workflow-linter.yml
#
# Load-bearing build/security workflows stay standalone in the repo
# (rust-ci, codeql, dependabot, release, scan/mirror/pages plumbing).
name: Governance
on:
push:
branches: [main, master]
pull_request:
workflow_dispatch:
# A called reusable workflow cannot request MORE permissions than its caller
# grants — if it does, the run is rejected before any job starts
# (startup_failure, zero jobs, no check run to inspect).
#
# standards@0ced540e ("chore: estate-wide security compliance", 2026-07-26)
# added `actions: read` to governance-reusable.yml's own permissions block.
# Because this caller pins the reusable at @main rather than a SHA, that change
# arrived immediately and broke Governance here. `actions: read` is mirrored
# below to match.
permissions:
actions: read
contents: read
jobs:
governance:
uses: hyperpolymath/standards/.github/workflows/governance-reusable.yml@fcb566cfb8a86cea2d3666bf65a4f177a49b1313
permissions:

Check failure on line 40 in .github/workflows/governance.yml

View workflow run for this annotation

GitHub Actions / .github/workflows/governance.yml

Invalid workflow file

You have an error in your yaml syntax on line 40
actions: read
contents: read
security-events: write