Tags: diffplug/dormouse
Tags
Permit actions: write on release.yml security-audit job in SECURITY.md The security audit caught its own gating change: dispatching the audit needs actions: write, which line 36 forbade for non-agent-managed workflows. Carve out that one job as an explicit, bounded exception (documented blast radius) so the policy matches the design and the audit's mechanical check passes. Dispatch is required because claude-code-action rejects the push event a workflow_call would inherit, and GITHUB_EVENT_NAME cannot be overridden. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
PreviousNext