Repository navigation
ci: use the built-in token in the Hacktoberfest workflow - #1778
Conversation
Reviewer's guide (collapsed on small PRs)Reviewer's GuideThe Hacktoberfest labeling job now uses the built-in GitHub token, with explicit contents and issue write permissions configured so the action can apply labels without a custom secret. File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
There was a problem hiding this comment.
Hey - I've reviewed your changes and they look great!
Sourcery assessment
Needs a human reviewer. This changes the workflow's authorization boundary by giving the built-in token contents and issues write access to a third-party action. If that action or its invocation is wrong or compromised, it could modify repository contents or issue records; reverting only prevents future access and does not undo those changes.
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #1778 +/- ##
=======================================
Coverage 99.92% 99.92%
=======================================
Files 37 37
Lines 1333 1333
Branches 71 71
=======================================
Hits 1332 1332
Partials 1 1 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
Committed via https://github.com/asottile/all-repos
Summary by Sourcery
Update the Hacktoberfest workflow to use the built-in GitHub token for labeling issues.
Enhancements:
CI: