Skip to content

Fix/SBOM pull requests permission#15

Merged
pgmac merged 3 commits into
masterfrom
fix/sbom-pull-requests-permission
May 4, 2026
Merged

Fix/SBOM pull requests permission#15
pgmac merged 3 commits into
masterfrom
fix/sbom-pull-requests-permission

Conversation

@pgmac
Copy link
Copy Markdown

@pgmac pgmac commented May 4, 2026

No description provided.

pgmac and others added 2 commits May 4, 2026 09:44
pg-actions commit f283f3f added pull-requests:write to the
GHAS-dependency-scan job. When a caller specifies explicit permissions,
the called workflow is restricted to only those permissions — GitHub
fails the workflow at startup if the called workflow requests more.

Adds pull-requests:write to the sbom.yml job-level permissions so the
reusable workflow can post PR comments again.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
The pg-actions reusable sbom.yml runs jdx/mise-action which reads the
calling repo's mise.toml. Without it, gh is not installed and the
attestation verify step fails.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@pgmac pgmac self-assigned this May 4, 2026
@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 4, 2026

Docker Build

Field Value
Status Built (not pushed -- PR build only)
Tag pr-15-cd71fc7
Commit cd71fc7

Image will be pushed to macro.int.pgmac.net:5000 on merge to master.
This comment is updated on each commit.

@pgmac pgmac merged commit ab74ecc into master May 4, 2026
2 checks passed
@pgmac pgmac deleted the fix/sbom-pull-requests-permission branch May 4, 2026 00:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant