Skip to content

Scope Dependabot dispatch permission#127

Merged
xpcmdshell merged 1 commit intomainfrom
feature/dependabot-dispatch-permission
Apr 5, 2026
Merged

Scope Dependabot dispatch permission#127
xpcmdshell merged 1 commit intomainfrom
feature/dependabot-dispatch-permission

Conversation

@xpcmdshell
Copy link
Copy Markdown
Owner

Summary

  • grant actions: write only to the refresh-behind-dependabot-prs job
  • keep workflow-wide permissions limited to contents and pull-requests write

Why

The refresh job needs actions: write to dispatch CI after updating a Dependabot branch. Scoping that permission to the one job keeps the workflow least-privilege while allowing the refresh path to work.

@xpcmdshell xpcmdshell merged commit a49ad9f into main Apr 5, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant