Skip to content

Commit ec622e0

Browse files
committed
fix(ci): scope review permissions to job level
1 parent 69f3a2d commit ec622e0

2 files changed

Lines changed: 10 additions & 6 deletions

File tree

.github/workflows/claude-review-manual.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -15,12 +15,14 @@ on:
1515

1616
permissions:
1717
contents: read
18-
pull-requests: write
19-
issues: write
20-
id-token: write
2118

2219
jobs:
2320
claude-review:
21+
permissions:
22+
contents: read
23+
pull-requests: write
24+
issues: write
25+
id-token: write
2426
uses: codingworkflow/codingworkflow-security-policies/.github/workflows/reusable-claude-review.yml@55070d1bc124fbe46d9a8edbc8d536826d4e15ed
2527
with:
2628
pr_number: ${{ inputs.pr_number }}

.github/workflows/opencode-review-manual.yml

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -30,12 +30,14 @@ on:
3030

3131
permissions:
3232
contents: read
33-
pull-requests: write
34-
issues: write
35-
id-token: write
3633

3734
jobs:
3835
opencode-review:
36+
permissions:
37+
contents: read
38+
pull-requests: write
39+
issues: write
40+
id-token: write
3941
uses: codingworkflow/codingworkflow-security-policies/.github/workflows/reusable-opencode-review.yml@55070d1bc124fbe46d9a8edbc8d536826d4e15ed
4042
with:
4143
pr_number: ${{ inputs.pr_number }}

0 commit comments

Comments
 (0)