State the Checks API gap instead of prescribing an impossible tick
Fine-grained tokens have no Checks permission. GitHub's permission reference lists no Checks section and no check-run endpoint, and checks is absent from the token form's pre-fill parameters, so the earlier instruction to tick Checks: Read asked for a box that does not exist. A token created with every listed permission still could not read check runs, which is what surfaced this. The prompt now states the consequence rather than offering a remedy: gh pr checks reports commit statuses only and gh run view returns no annotations. Both degrade to empty output rather than a permission error, so without the note they read as a broken CI integration. Job logs are unaffected; they fall under Actions, which is granted. secret_scanning_alerts and vulnerability_alerts move into the pre-filled URL, leaving nothing for the operator to tick beyond repository selection.
This commit is contained in:
@@ -69,11 +69,14 @@ for expected in secret_scanning_alerts=read vulnerability_alerts=read statuses=r
|
||||
fail "permission dropped out of the pre-filled URL: $expected"
|
||||
done
|
||||
|
||||
((${#TOKEN_MANUAL_PERMISSIONS[@]})) ||
|
||||
fail "the manual checklist is empty; checks is not pre-fillable and must be listed"
|
||||
((${#TOKEN_LIMITATIONS[@]})) ||
|
||||
fail "the limitations list is empty; the Checks gap must be stated"
|
||||
|
||||
printf '%s\n' "${TOKEN_MANUAL_PERMISSIONS[@]}" | grep -q 'Checks' ||
|
||||
fail "the manual checklist must name Checks"
|
||||
printf '%s\n' "${TOKEN_LIMITATIONS[@]}" | grep -q 'gh pr checks' ||
|
||||
fail "the limitations must name gh pr checks"
|
||||
|
||||
printf '%s\n' "${TOKEN_LIMITATIONS[@]}" | grep -qi 'tick\|check the box' &&
|
||||
fail "the limitations must not imply Checks can be granted"
|
||||
|
||||
if ((failures)); then
|
||||
printf '%d assertion(s) failed\n' "$failures" >&2
|
||||
|
||||
Reference in New Issue
Block a user