From ffdacd56ea31cb3f8268c3e88a7f3601c7657ea3 Mon Sep 17 00:00:00 2001 From: Michael Dieringer <65093775+MichaelDieringer@users.noreply.github.com> Date: Wed, 22 Jul 2026 12:26:03 +0200 Subject: [PATCH] Fix PR #9: revert invalid 'workflows: write' permission, strip workflow-file changes from sync branch instead PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission scope (verified list: actions, contents, issues, pull-requests, etc. - no 'workflows'). Merging it broke workflow_dispatch outright: Invalid Argument - failed to parse workflow: (Line: 21, Col: 3): Unexpected value 'workflows' GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard GitHub restriction, not something the permissions: block controls. The correct fix is to never let the sync branch carry workflow-file changes in the first place: after a clean merge, restore .github/workflows from origin/main and amend. This also closes a latent risk - a clean upstream merge could otherwise silently overwrite QualityHub's own CI files (including this one) with whatever microsoft/BCQuality ships under the same paths. --- .github/workflows/upstream-watch.yml | 12 ++++++++++-- 1 file changed, 10 insertions(+), 2 deletions(-) diff --git a/.github/workflows/upstream-watch.yml b/.github/workflows/upstream-watch.yml index 71b49c9..8e89eb3 100644 --- a/.github/workflows/upstream-watch.yml +++ b/.github/workflows/upstream-watch.yml @@ -18,8 +18,6 @@ permissions: contents: write pull-requests: write issues: write - workflows: write # upstream commits ofte selv .github/workflows/* filer - - # uden dette afviser GitHub push af sync-branchen jobs: round: @@ -55,6 +53,16 @@ jobs: echo "branch=$BRANCH" >> "$GITHUB_OUTPUT" git checkout -B "$BRANCH" origin/main if git merge upstream/main --no-edit; then + # QualityHub owns its own CI - GITHUB_TOKEN can never push + # .github/workflows/* changes (hard GitHub restriction, not a + # permissions:-block setting), and silently inheriting + # upstream's workflow files would risk overwriting our own + # (including this file). Drop any workflow-file changes the + # merge brought in before the branch is ever pushed. + if ! git diff --quiet origin/main -- .github/workflows; then + git checkout origin/main -- .github/workflows + git commit --amend --no-edit + fi echo "clean=true" >> "$GITHUB_OUTPUT" else echo "clean=false" >> "$GITHUB_OUTPUT"