mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 22:56:55 +01:00
Fix PR #9: revert invalid 'workflows: write' permission, strip workflow-file changes from sync branch instead
PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission scope (verified list: actions, contents, issues, pull-requests, etc. - no 'workflows'). Merging it broke workflow_dispatch outright: Invalid Argument - failed to parse workflow: (Line: 21, Col: 3): Unexpected value 'workflows' GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard GitHub restriction, not something the permissions: block controls. The correct fix is to never let the sync branch carry workflow-file changes in the first place: after a clean merge, restore .github/workflows from origin/main and amend. This also closes a latent risk - a clean upstream merge could otherwise silently overwrite QualityHub's own CI files (including this one) with whatever microsoft/BCQuality ships under the same paths.
This commit is contained in:
parent
ffc0b8286f
commit
ffdacd56ea
1 changed files with 10 additions and 2 deletions
12
.github/workflows/upstream-watch.yml
vendored
12
.github/workflows/upstream-watch.yml
vendored
|
|
@ -18,8 +18,6 @@ permissions:
|
|||
contents: write
|
||||
pull-requests: write
|
||||
issues: write
|
||||
workflows: write # upstream commits ofte selv .github/workflows/* filer -
|
||||
# uden dette afviser GitHub push af sync-branchen
|
||||
|
||||
jobs:
|
||||
round:
|
||||
|
|
@ -55,6 +53,16 @@ jobs:
|
|||
echo "branch=$BRANCH" >> "$GITHUB_OUTPUT"
|
||||
git checkout -B "$BRANCH" origin/main
|
||||
if git merge upstream/main --no-edit; then
|
||||
# QualityHub owns its own CI - GITHUB_TOKEN can never push
|
||||
# .github/workflows/* changes (hard GitHub restriction, not a
|
||||
# permissions:-block setting), and silently inheriting
|
||||
# upstream's workflow files would risk overwriting our own
|
||||
# (including this file). Drop any workflow-file changes the
|
||||
# merge brought in before the branch is ever pushed.
|
||||
if ! git diff --quiet origin/main -- .github/workflows; then
|
||||
git checkout origin/main -- .github/workflows
|
||||
git commit --amend --no-edit
|
||||
fi
|
||||
echo "clean=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "clean=false" >> "$GITHUB_OUTPUT"
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue