Fix PR #9: revert invalid 'workflows: write' permission, strip workflow-file changes from sync branch instead

PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission
scope (verified list: actions, contents, issues, pull-requests, etc. - no
'workflows'). Merging it broke workflow_dispatch outright:

  Invalid Argument - failed to parse workflow: (Line: 21, Col: 3):
  Unexpected value 'workflows'

GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard
GitHub restriction, not something the permissions: block controls. The
correct fix is to never let the sync branch carry workflow-file changes in
the first place: after a clean merge, restore .github/workflows from
origin/main and amend. This also closes a latent risk - a clean upstream
merge could otherwise silently overwrite QualityHub's own CI files
(including this one) with whatever microsoft/BCQuality ships under the same
paths.
This commit is contained in:
Michael Dieringer 2026-07-22 12:26:03 +02:00
parent ffc0b8286f
commit ffdacd56ea

View file

@ -18,8 +18,6 @@ permissions:
contents: write contents: write
pull-requests: write pull-requests: write
issues: write issues: write
workflows: write # upstream commits ofte selv .github/workflows/* filer -
# uden dette afviser GitHub push af sync-branchen
jobs: jobs:
round: round:
@ -55,6 +53,16 @@ jobs:
echo "branch=$BRANCH" >> "$GITHUB_OUTPUT" echo "branch=$BRANCH" >> "$GITHUB_OUTPUT"
git checkout -B "$BRANCH" origin/main git checkout -B "$BRANCH" origin/main
if git merge upstream/main --no-edit; then if git merge upstream/main --no-edit; then
# QualityHub owns its own CI - GITHUB_TOKEN can never push
# .github/workflows/* changes (hard GitHub restriction, not a
# permissions:-block setting), and silently inheriting
# upstream's workflow files would risk overwriting our own
# (including this file). Drop any workflow-file changes the
# merge brought in before the branch is ever pushed.
if ! git diff --quiet origin/main -- .github/workflows; then
git checkout origin/main -- .github/workflows
git commit --amend --no-edit
fi
echo "clean=true" >> "$GITHUB_OUTPUT" echo "clean=true" >> "$GITHUB_OUTPUT"
else else
echo "clean=false" >> "$GITHUB_OUTPUT" echo "clean=false" >> "$GITHUB_OUTPUT"