mirror of
https://github.com/microsoft/BCQuality.git
synced 2026-10-05 14:46:55 +01:00
Fix PR #9: revert invalid 'workflows: write' permission, strip workflow-file changes from sync branch instead
PR #9's fix was wrong: 'workflows' is not a real GitHub Actions permission scope (verified list: actions, contents, issues, pull-requests, etc. - no 'workflows'). Merging it broke workflow_dispatch outright: Invalid Argument - failed to parse workflow: (Line: 21, Col: 3): Unexpected value 'workflows' GITHUB_TOKEN can never push .github/workflows/* changes - that's a hard GitHub restriction, not something the permissions: block controls. The correct fix is to never let the sync branch carry workflow-file changes in the first place: after a clean merge, restore .github/workflows from origin/main and amend. This also closes a latent risk - a clean upstream merge could otherwise silently overwrite QualityHub's own CI files (including this one) with whatever microsoft/BCQuality ships under the same paths.
This commit is contained in:
parent
ffc0b8286f
commit
ffdacd56ea
1 changed files with 10 additions and 2 deletions
12
.github/workflows/upstream-watch.yml
vendored
12
.github/workflows/upstream-watch.yml
vendored
|
|
@ -18,8 +18,6 @@ permissions:
|
||||||
contents: write
|
contents: write
|
||||||
pull-requests: write
|
pull-requests: write
|
||||||
issues: write
|
issues: write
|
||||||
workflows: write # upstream commits ofte selv .github/workflows/* filer -
|
|
||||||
# uden dette afviser GitHub push af sync-branchen
|
|
||||||
|
|
||||||
jobs:
|
jobs:
|
||||||
round:
|
round:
|
||||||
|
|
@ -55,6 +53,16 @@ jobs:
|
||||||
echo "branch=$BRANCH" >> "$GITHUB_OUTPUT"
|
echo "branch=$BRANCH" >> "$GITHUB_OUTPUT"
|
||||||
git checkout -B "$BRANCH" origin/main
|
git checkout -B "$BRANCH" origin/main
|
||||||
if git merge upstream/main --no-edit; then
|
if git merge upstream/main --no-edit; then
|
||||||
|
# QualityHub owns its own CI - GITHUB_TOKEN can never push
|
||||||
|
# .github/workflows/* changes (hard GitHub restriction, not a
|
||||||
|
# permissions:-block setting), and silently inheriting
|
||||||
|
# upstream's workflow files would risk overwriting our own
|
||||||
|
# (including this file). Drop any workflow-file changes the
|
||||||
|
# merge brought in before the branch is ever pushed.
|
||||||
|
if ! git diff --quiet origin/main -- .github/workflows; then
|
||||||
|
git checkout origin/main -- .github/workflows
|
||||||
|
git commit --amend --no-edit
|
||||||
|
fi
|
||||||
echo "clean=true" >> "$GITHUB_OUTPUT"
|
echo "clean=true" >> "$GITHUB_OUTPUT"
|
||||||
else
|
else
|
||||||
echo "clean=false" >> "$GITHUB_OUTPUT"
|
echo "clean=false" >> "$GITHUB_OUTPUT"
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue