Potential fix for code scanning alert no. 14: Workflow does not contain permissions #270
release-drafter.yml
on: pull_request
update_release_draft
7s
Annotations
2 errors and 4 warnings
|
update_release_draft
HttpError: Validation Failed: {"resource":"Release","code":"invalid","field":"target_commitish"}
at /home/runner/work/_actions/release-drafter/release-drafter/v6/dist/index.js:7146:21
at process.processTicksAndRejections (node:internal/process/task_queues:95:5)
at async Job.doExecute (/home/runner/work/_actions/release-drafter/release-drafter/v6/dist/index.js:61885:18)
{
name: 'AggregateError',
event: {
id: '18289703933',
name: 'pull_request',
payload: {
action: 'opened',
number: 1613,
organization: {
avatar_url: 'https://avatars.githubusercontent.com/u/106463282?v=4',
description: 'An Opensource platform for React developers to learn, create and share ReactJS Projects. ',
events_url: 'https://api.github.com/orgs/reactplay/events',
hooks_url: 'https://api.github.com/orgs/reactplay/hooks',
id: 106463282,
issues_url: 'https://api.github.com/orgs/reactplay/issues',
login: 'reactplay',
members_url: 'https://api.github.com/orgs/reactplay/members{/member}',
node_id: 'O_kgDOBliAMg',
public_members_url: 'https://api.github.com/orgs/reactplay/public_members{/member}',
repos_url: 'https://api.github.com/orgs/reactplay/repos',
url: 'https://api.github.com/orgs/reactplay'
},
pull_request: {
_links: {
comments: {
href: 'https://api.github.com/repos/reactplay/react-play/issues/1613/comments'
},
commits: {
href: 'https://api.github.com/repos/reactplay/react-play/pulls/1613/commits'
},
html: { href: 'https://github.com/reactplay/react-play/pull/1613' },
issue: {
href: 'https://api.github.com/repos/reactplay/react-play/issues/1613'
},
review_comment: {
href: 'https://api.github.com/repos/reactplay/react-play/pulls/comments{/number}'
},
review_comments: {
href: 'https://api.github.com/repos/reactplay/react-play/pulls/1613/comments'
},
self: {
href: 'https://api.github.com/repos/reactplay/react-play/pulls/1613'
},
statuses: {
href: 'https://api.github.com/repos/reactplay/react-play/statuses/9d27fa805b4eb646c4e9248740d78de6c686a509'
}
},
active_lock_reason: null,
additions: 2,
assignee: null,
assignees: [],
author_association: 'MEMBER',
auto_merge: null,
base: {
label: 'reactplay:main',
ref: 'main',
repo: {
allow_auto_merge: false,
allow_forking: true,
allow_merge_commit: false,
allow_rebase_merge: false,
allow_squash_merge: true,
allow_update_branch: true,
archive_url: 'https://api.github.com/repos/reactplay/react-play/{archive_format}{/ref}',
archived: false,
assignees_url: 'https://api.github.com/repos/reactplay/react-play/assignees{/user}',
blobs_url: 'https://api.github.com/repos/reactplay/react-play/git/blobs{/sha}',
branches_url: 'https://api.github.com/repos/reactplay/react-play/branches{/branch}',
clone_url: 'https://github.com/reactplay/react-play.git',
collaborators_url: 'https://api.github.com/repos/reactplay/react-play/collaborators{/collaborator}',
comments_url: 'https://api.github.com/repos/reactplay/react-play/comments{/number}',
commits_url: 'https://api.github.com/repos/reactplay/react-play/commits{/sha}',
compare_url: 'https://api.github.com/repos/reactplay/react-play/compare/{base}...{head}',
contents_url: 'https://api.github.com/repos/reactplay/react-play/contents/{+path}',
contributors_url: 'https://api.github.com/repos/reactplay/react-play/contributors',
created_at: '2022-01-10T07:04:24Z',
default_branch: 'main',
delete_branch_on_merge: true,
deployments_url: 'https:
|
|
update_release_draft
Validation Failed: {"resource":"Release","code":"invalid","field":"target_commitish"}
{
name: 'HttpError',
id: '18289703933',
status: 422,
response: {
url: 'https://api.github.com/repos/reactplay/react-play/releases/179729390',
status: 422,
headers: {
'access-control-allow-origin': '*',
'access-control-expose-headers': 'ETag, Link, Location, Retry-After, X-GitHub-OTP, X-RateLimit-Limit, X-RateLimit-Remaining, X-RateLimit-Used, X-RateLimit-Resource, X-RateLimit-Reset, X-OAuth-Scopes, X-Accepted-OAuth-Scopes, X-Poll-Interval, X-GitHub-Media-Type, X-GitHub-SSO, X-GitHub-Request-Id, Deprecation, Sunset',
'content-length': '210',
'content-security-policy': "default-src 'none'",
'content-type': 'application/json; charset=utf-8',
date: 'Mon, 06 Oct 2025 17:49:50 GMT',
'referrer-policy': 'origin-when-cross-origin, strict-origin-when-cross-origin',
server: 'github.com',
'strict-transport-security': 'max-age=31536000; includeSubdomains; preload',
vary: 'Accept-Encoding, Accept, X-Requested-With',
'x-accepted-github-permissions': 'contents=write',
'x-content-type-options': 'nosniff',
'x-frame-options': 'deny',
'x-github-api-version-selected': '2022-11-28',
'x-github-media-type': 'github.v3; format=json',
'x-github-request-id': '0C31:C0515:A07C23:28A6C72:68E4013E',
'x-ratelimit-limit': '5000',
'x-ratelimit-remaining': '4848',
'x-ratelimit-reset': '1759773387',
'x-ratelimit-resource': 'core',
'x-ratelimit-used': '152',
'x-xss-protection': '0'
},
data: {
message: 'Validation Failed',
errors: [
{
resource: 'Release',
code: 'invalid',
field: 'target_commitish'
}
],
documentation_url: 'https://docs.github.com/rest/releases/releases#update-a-release',
status: '422'
}
},
request: {
method: 'PATCH',
url: 'https://api.github.com/repos/reactplay/react-play/releases/179729390',
headers: {
accept: 'application/vnd.github.v3+json',
'user-agent': 'probot/12.4.0 octokit-core.js/3.6.0 Node.js/20.19.4 (linux; x64)',
'x-github-delivery': '18289703933',
authorization: 'token [REDACTED]',
'content-type': 'application/json; charset=utf-8'
},
body: '{"body":"## Changes\\n\\n- fix: Ensure header button border remain visible on mobile hover/focus @Rohs21 (#1602)\\n- Added text-to-speech play @Ritesh381 (#1604)\\n- refactor: enhance PlayCard and Like components for improved UI and functionality @aayu5hgit (#1605)\\n- fix: [Bug report]: The build failed with the following error @sabeerwaqas (#1609)\\n- Added Contributor Guidelines confirmation checkbox to templates @Aditya-Bajpayee007 (#1608)\\n- Fix/password generator img @saatvik-10 (#1586)\\n- fix: add missing cover image for password-generator @saatvik-10 (#1585)\\n- fix: eslint issues that were failing local dev server @supminn (#1583)\\n- Removed issue-unassign workflow @Abhishek-90 (#1579)\\n- feat: add steps play @aaqib605 (#1572)\\n- Add Validation for URL Shortener Buttons and Fix Placeholder Visibility Issue @anuj-kumary (#1577)\\n- fix: total value shows NaN when an expense with 0 amount @anuj-kumary (#1574)\\n- Improved PlayHeader(#1562) @joshua-jinu (#1568)\\n- feat(plays): add dictionary play @Ananya-Bhardwaj (#1567)\\n- Added Selection Sort Visualizer Project in plays folder @ananya8606 (#1563)\\n- Daily Diary @GhadaRV (#1564)\\n- fix: Made clickable links and made badges page responsive @KrishDave1 (#1565)\\n- (feat) Improved UI of play Typing Speed Test @BayajidAlam (#1558)\\n- (refactor) constant/index.js file @saddamhr (#1561)\\n- fix: Ensure consistent checkbox behavior in Language filter (#1519) @Arun-cn (#1557)\\n- docs: add saddamhr as a contributor for code @[allcontributors[bot]](https://github.com/apps/allcontributors) (#1560)\\n- Feature/play/zoomlogin refactor1 @day-lee (#1554)\\n- Merge Request: New Play - BMI Calculator @Adil-Khan-N (#1549)\\n- Changes to be committed: Added Cheesy Pick
|
|
update_release_draft
"pull_request_target.edited" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
update_release_draft
"pull_request_target.synchronize" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
update_release_draft
"pull_request_target.reopened" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|
|
update_release_draft
"pull_request_target.opened" is not a known webhook name (https://developer.github.com/v3/activity/events/types/)
|