Repository navigation
[Idea] Setting to extend workflow permissions #2374
Ole Wunschmann (OleWunschmann)
started this conversation in
Ideas
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Idea Description
Repositories can add custom jobs to existing workflows, but those jobs are limited to the permissions already defined by AL-Go.
Example:
The
PullRequestHandler.yamlworkflow has the permissionpull-requests: read.Therefore, there is no straightforward way to add a custom job that posts comments on a pull request.
A current workaround is to use an additional GitHub App with the required permissions.
Idea:
Introduce a new
WorkflowPermissionssetting similar to the setting for schedules.It could be an object containing custom permissions as properties, for example:
{ "pull-requests": "write" }The update workflow would read this setting and replace or update the permissions for each specified property.
There could also be a restriction that this setting may only increase permissions and permission reductions would be ignored.
For example, if a workflow has
pull-requests: read, it must not be possible to change it topull-requests: none.Contribution (Optional)
All reactions