Skip to content

fix(dependency-review): reusable workflow causes caller startup_failure #1733

Description

@seonghobae

Superseded by existing canonical owner repair

Fresh owner-path search after opening this issue found the already-existing canonical .github repair PR #1725, which has independently reproduced this exact failure class on newsdom-api and mightyETL and identifies the causal defect: reusable workflows cannot elevate the caller's GITHUB_TOKEN permission envelope. Consumer callers that omitted contents: read + pull-requests: read terminate startup_failure with zero jobs.

Naruon #1539@6e7a8d8a947fec1ffdfff15f165b3a171ec2e03e is now added as a fifth exact reproduction on #1725, and the Naruon consumer PR has been given the minimal caller-side repair/verification criteria.

This issue adds no unique remaining delta beyond #1725; keeping a duplicate owner issue would split provenance. Close as duplicate only because the existing canonical owner PR fully owns the same root cause, RED/GREEN contract, immutable publication requirement, and consumer revalidation path.

Canonical owner: #1725
Affected consumer: ContextualWisdomLab/naruon#1539
Exact failed run: naruon 33630975578 on 6e7a8d8a947fec1ffdfff15f165b3a171ec2e03e.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: ci-cdCI, GitHub Actions, checks, release, or supply chainarea: securitySecurity boundary, hardening, or vulnerability preventionbugSomething isn't workingpriority: highHigh-priority or P1 workstatus: blockedBlocked by conflict, dependency, or required prerequisitetype: bugDefect or incorrect behavior

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions