Skip to content

fix(release): grant actions:read so preflight can see pr.yml - #53

Merged
antosubash merged 1 commit into
mainfrom
feature/kind-chandrasekhar-f4fb12
Apr 22, 2026
Merged

antosubash merged 1 commit into
mainfrom
feature/kind-chandrasekhar-f4fb12

Conversation

@antosubash

Copy link
Copy Markdown
Owner

Summary

  • The latest release run (24779237370) failed in preflight with a 5-minute timeout waiting for pr.yml, even though pr.yml on the same commit had already completed green at 12:53:34Z.
  • Root cause: the workflow-level permissions: block listed only contents: write and id-token: write. Specifying any scope implicitly sets every other scope to none, so actions was none, gh run list returned empty, and 2>/dev/null || true swallowed the underlying error. The poll loop never saw completed.
  • Fix: add actions: read to the permissions block, and drop 2>/dev/null so future gh errors are visible in the log.

Test plan

  • Merge and re-dispatch release against main (testpypi target) once pr.yml is green — preflight should now detect the green run and advance to build.

The workflow-level permissions block only listed contents/id-token, which
implicitly set actions to none. gh run list then returned nothing, the
2>/dev/null swallowed the error, and preflight spun out its 5-minute
timeout even though pr.yml had already finished green.

- add actions: read to the permissions block
- drop 2>/dev/null so future gh failures are visible in the log
@antosubash
antosubash merged commit b4009cc into main Apr 22, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant