From dbf933d206d869fd9df98d70c4a56857ec272f95 Mon Sep 17 00:00:00 2001 From: Anto Subash Date: Wed, 22 Apr 2026 15:51:25 +0200 Subject: [PATCH] fix(release): grant actions:read so preflight can see pr.yml status The workflow-level permissions block only listed contents/id-token, which implicitly set actions to none. gh run list then returned nothing, the 2>/dev/null swallowed the error, and preflight spun out its 5-minute timeout even though pr.yml had already finished green. - add actions: read to the permissions block - drop 2>/dev/null so future gh failures are visible in the log --- .github/workflows/release.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index d9fe08b7..4c155746 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -16,6 +16,7 @@ on: permissions: contents: write id-token: write # required for PyPI Trusted Publishing (OIDC); npm uses NPM_TOKEN + actions: read # preflight's `gh run list` needs this; omitting it silently returns empty env: NODE_VERSION: "24" @@ -54,7 +55,7 @@ jobs: --workflow pr.yml \ --branch main \ --json conclusion,status \ - --jq 'map(select(.status == "completed")) | .[0].conclusion' 2>/dev/null || true) + --jq 'map(select(.status == "completed")) | .[0].conclusion' || true) case "${conclusion:-}" in success) echo "pr.yml passed on ${{ github.sha }}"