From 177dc057a4e6fec1abe317421c1fe0c4cc58403e Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Fri, 5 Jun 2026 12:18:52 -0400 Subject: [PATCH] fix(ci): drop pull-requests write from callable-dependency-review Callers grant no explicit permissions, so they pass the org default read-only token. A reusable workflow cannot request more than its caller grants, causing startup_failure on every dependency-review run. dependency-review-action only needs contents: read when not posting PR comments. --- .github/workflows/callable-dependency-review.yaml | 1 - 1 file changed, 1 deletion(-) diff --git a/.github/workflows/callable-dependency-review.yaml b/.github/workflows/callable-dependency-review.yaml index 646225b..a0a3f7a 100644 --- a/.github/workflows/callable-dependency-review.yaml +++ b/.github/workflows/callable-dependency-review.yaml @@ -3,7 +3,6 @@ on: workflow_call: permissions: contents: read - pull-requests: write jobs: dependency-review: runs-on: ubuntu-latest