Skip to content

Commit 21e14f3

Browse files
committed
fix: add permissions to attempt-fix-io workflow job
The attempt-fix-io job calls fuzzer-fix-automation.yml which requires write permissions for contents, issues, pull-requests, and id-token. When using workflow_call, the called workflow inherits permissions from the caller, so we need to explicitly grant these permissions. This fixes the error: "The nested job 'attempt-fix' is requesting 'contents: write, issues: write, pull-requests: write, id-token: write', but is only allowed 'contents: read, issues: none, pull-requests: none, id-token: none'." Signed-off-by: Joe Isaacs <[email protected]>
1 parent bd6e37a commit 21e14f3

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

.github/workflows/fuzz.yml

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -129,6 +129,11 @@ jobs:
129129
name: "Attempt Fix for IO Fuzz Crash"
130130
needs: report-io-fuzz-failures
131131
if: needs.report-io-fuzz-failures.outputs.issue_number != ''
132+
permissions:
133+
contents: write
134+
issues: write
135+
pull-requests: write
136+
id-token: write
132137
uses: ./.github/workflows/fuzzer-fix-automation.yml
133138
with:
134139
issue_number: ${{ needs.report-io-fuzz-failures.outputs.issue_number }}

0 commit comments

Comments
 (0)