Skip to content

security: update and pin workflow action dependencies#749

Merged
krajorama merged 2 commits into
mainfrom
krajo/harden-ci
Jun 24, 2026
Merged

security: update and pin workflow action dependencies#749
krajorama merged 2 commits into
mainfrom
krajo/harden-ci

Conversation

@krajorama

Copy link
Copy Markdown
Member

Also remove master branch from the list.

krajorama and others added 2 commits June 24, 2026 08:39
Also remove master branch from the list.

Signed-off-by: György Krajcsovits <gyorgy.krajcsovits@grafana.com>
The action's API calls (listFiles, create/delete comment) operate on a
pull request, which GitHub governs under the pull-requests permission
rather than issues. The previous issues: write scope granted nothing the
action could use, causing "Resource not accessible by integration".

Signed-off-by: György Krajcsovits <gyorgy.krajcsovits@grafana.com>
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@github-actions

Copy link
Copy Markdown

Thanks for opening this pull request! Each pull request require an update in the CHANGELOG. Please update it based on your changes.

@krajorama

Copy link
Copy Markdown
Member Author

Thanks for opening this pull request! Each pull request require an update in the CHANGELOG. Please update it based on your changes.

This PR touches CI only, not user visible. I'll follow what we do in Prometheus and not add it to the CHANGELOG. Feel free to open a PR to add it anyway.

@krajorama krajorama merged commit c34d15c into main Jun 24, 2026
14 checks passed
@krajorama krajorama mentioned this pull request Jun 24, 2026
@ArthurSens ArthurSens deleted the krajo/harden-ci branch June 24, 2026 08:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant