Skip to content

fix(ci): grant the wrapper the permissions the reusable declares - #72

Merged
hyperpolymath merged 1 commit into
mainfrom
fix/hypatia-wrapper-permissions
Sep 21, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
fix/hypatia-wrapper-permissions

Conversation

@hyperpolymath

Copy link
Copy Markdown
Owner

Every run of this wrapper was startup_failure — the workflow never started, so the repository has never published a Hypatia check. That is the defect class of hyperpolymath/tropical-types#17: a gate (or a requirement) that names a context nothing publishes.

Cause: the Hypatia reusable workflow declares actions: read, contents: read and security-events: write, and a caller cannot start a called workflow unless its job grants at least what the called workflow declares. This wrapper did not grant actions: read.

Fix, minimal:

  • grant actions: read (at the job level where a job-level permissions: block overrides the workflow-level one);
  • pass secrets: inherit — the reusable consumes secrets.HYPATIA_SCAN_PAT || secrets.GITHUB_TOKEN.

The caller id, the pin and the rest of the job are untouched. Found by the caller-id standardisation sweep (same probe: read the run history, not the file).

The Hypatia reusable workflow declares `actions: read`, `contents: read` and
`security-events: write`. A caller job that does not grant at least what the
called workflow declares cannot start at all: every run of this wrapper was
`startup_failure`, so the repository published no Hypatia check — the defect
class of hyperpolymath/tropical-types#17 (a gate that names a context with no
publisher).

* grant `actions: read`
* pass `secrets: inherit` (the reusable consumes
  `secrets.HYPATIA_SCAN_PAT || secrets.GITHUB_TOKEN`)

No other change: the caller id, the pin, and the job body are untouched.
@coderabbitai

coderabbitai Bot commented Sep 21, 2026

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 12 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0123f878-084e-4ff1-9173-03985a56cfb4

📥 Commits

Reviewing files that changed from the base of the PR and between 30e02dc and 319f470.

📒 Files selected for processing (1)
  • .github/workflows/hypatia-scan.yml

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@hyperpolymath
hyperpolymath merged commit 6c1be81 into main Sep 21, 2026
12 of 16 checks passed
@hyperpolymath
hyperpolymath deleted the fix/hypatia-wrapper-permissions branch September 21, 2026 00:07
jobs:
hypatia:
uses: hyperpolymath/standards/.github/workflows/hypatia-scan-reusable.yml@571cc734cd69fb846032ec77a662aa8ee4fc32cd

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants