deckhearth/.github
varutasu 7e972546b7
fix(ci): scoped permissions for preview-smoke + visual-diff workflows (#16)
Both Playwright-on-Vercel workflows fail at the very first action
(`patrickedqvist/wait-for-vercel-preview@v1.3.2`) with 403 "Resource
not accessible by integration". The cause is the repo-default workflow
token being read-only-by-default with no scopes declared by the workflow.

Add minimal scoped permission blocks per the GitHub Actions least-privilege
guidance:

  preview-smoke.yml:
    contents: read
    deployments: read   # wait-for-vercel-preview queries GitHub Deployments
    pull-requests: read # correlate deployment with this PR
    statuses: read      # some Vercel deployments use commit statuses

  visual-diff.yml:
    contents: read
    deployments: read
    pull-requests: write # final step posts "Visual Diff" comment via Issues API
    statuses: read

Verified against the failure on PR #15:
  - Playwright smoke: "Resource not accessible by integration" on
    wait-for-vercel-preview → fixed by deployments+statuses+pull-requests:read
  - Screenshot diff: 403 from POST /repos/.../issues/15/comments with
    `x-accepted-github-permissions: issues=write; pull_requests=write`
    in the response → fixed by pull-requests:write (covers Issues API
    for PR comments; issues:write would also work but pull-requests:write
    is the idiomatic scope)

Unblocks visual-regression signal on every future PR. No code changes,
no test changes — workflow YAML only.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-24 14:22:12 -05:00
..
workflows fix(ci): scoped permissions for preview-smoke + visual-diff workflows (#16) 2026-05-24 14:22:12 -05:00
CODEOWNERS bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00
PULL_REQUEST_TEMPLATE.md bootstrap: agent pipeline v0.5.0 + ship-readiness review 2026-05-23 02:31:26 -05:00