Skip to content

fix: correct Claude bot permissions - #78

Merged
dceoy merged 1 commit into
mainfrom
fix/claude-workflow-permissions
Aug 14, 2026
Merged

dceoy merged 1 commit into
mainfrom
fix/claude-workflow-permissions

Conversation

@dceoy

@dceoy dceoy commented Aug 14, 2026

Copy link
Copy Markdown
Owner

Summary

  • grant contents: write to the Claude mention-bot caller job
  • keep the PR review job read-only
  • retain id-token: write, which is part of the upstream Claude Code Action permission set

Rationale

The reusable claude-code-bot.yml requests contents: write, but a reusable workflow cannot elevate GITHUB_TOKEN permissions above those granted by its caller. The caller currently grants only contents: read, preventing Claude from applying repository content changes when invoked by an authorized mention.

The reusable workflow already restricts execution to OWNER, MEMBER, or COLLABORATOR authors.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Your trial has ended. Reactivate Greptile to resume code reviews.

@dceoy
dceoy merged commit 42f9fac into main Aug 14, 2026
6 checks passed
@dceoy
dceoy deleted the fix/claude-workflow-permissions branch August 14, 2026 02:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant