State the Checks API gap instead of prescribing an impossible tick

Fine-grained tokens have no Checks permission. GitHub's permission reference
lists no Checks section and no check-run endpoint, and checks is absent from
the token form's pre-fill parameters, so the earlier instruction to tick
Checks: Read asked for a box that does not exist. A token created with every
listed permission still could not read check runs, which is what surfaced this.

The prompt now states the consequence rather than offering a remedy: gh pr
checks reports commit statuses only and gh run view returns no annotations.
Both degrade to empty output rather than a permission error, so without the
note they read as a broken CI integration. Job logs are unaffected; they fall
under Actions, which is granted.

secret_scanning_alerts and vulnerability_alerts move into the pre-filled URL,
leaving nothing for the operator to tick beyond repository selection.
This commit is contained in:
2026-07-31 08:48:26 -05:00
parent b8bf9f9eff
commit 5e167d3a0d
3 changed files with 47 additions and 26 deletions
+7 -4
View File
@@ -69,11 +69,14 @@ for expected in secret_scanning_alerts=read vulnerability_alerts=read statuses=r
fail "permission dropped out of the pre-filled URL: $expected"
done
((${#TOKEN_MANUAL_PERMISSIONS[@]})) ||
fail "the manual checklist is empty; checks is not pre-fillable and must be listed"
((${#TOKEN_LIMITATIONS[@]})) ||
fail "the limitations list is empty; the Checks gap must be stated"
printf '%s\n' "${TOKEN_MANUAL_PERMISSIONS[@]}" | grep -q 'Checks' ||
fail "the manual checklist must name Checks"
printf '%s\n' "${TOKEN_LIMITATIONS[@]}" | grep -q 'gh pr checks' ||
fail "the limitations must name gh pr checks"
printf '%s\n' "${TOKEN_LIMITATIONS[@]}" | grep -qi 'tick\|check the box' &&
fail "the limitations must not imply Checks can be granted"
if ((failures)); then
printf '%d assertion(s) failed\n' "$failures" >&2