Skip to content

Read upgraded streams through the buffered reader #63

Read upgraded streams through the buffered reader

Read upgraded streams through the buffered reader #63

Workflow file for this run

name: PR Review
permissions:
contents: read # Required at top-level to give `issue_comment` events access to the secrets below.
# workflow_run is used deliberately here: the unprivileged "PR Review - Trigger"
# workflow runs on the fork PR and this privileged one only consumes its
# artifacts, never checks out or executes fork code.
on: # zizmor: ignore[dangerous-triggers]
issue_comment:
types: [ created ]
workflow_run:
workflows: [ "PR Review - Trigger" ]
types: [ completed ]
jobs:
review:

Check failure on line 17 in .github/workflows/pr-review.yml

View workflow run for this annotation

GitHub Actions / PR Review

Invalid workflow file

The workflow is not valid. .github/workflows/pr-review.yml (Line: 17, Col: 3): Error calling workflow 'docker/docker-agent-action/.github/workflows/review-pr.yml@4dcb32aa716addc5ce33f8b4d33cb635ae174d7e'. The nested job 'review' is requesting 'actions: write', but is only allowed 'actions: read'.
uses: docker/docker-agent-action/.github/workflows/review-pr.yml@4dcb32aa716addc5ce33f8b4d33cb635ae174d7e # v2.0.6
permissions:
contents: read # Read repository files and PR diffs
pull-requests: write # Post review comments
issues: write # Create security incident issues if secrets detected
checks: write # (Optional) Show review progress as a check run
id-token: write # Required for OIDC authentication to AWS Secrets Manager
actions: read # Download artifacts from trigger workflow
with:
trigger-run-id: ${{ github.event_name == 'workflow_run' && format('{0}', github.event.workflow_run.id) || '' }}