Skip to content

false positive? excessive-permissions on a reusable workflow with perms defined in parent caller. #471

Answered by woodruffw
userdocs asked this question in Q&A
Discussion options

You must be logged in to vote

Ah yep, that looks like a FP -- I made the excessive-permissions audit more general with this past release, but it looks like it doesn't adequately handle the reusable workflow "permissions from the caller" case.

Could you file a bug for that, with a full reproducer? I'll need to think a bit about how best to handle that, since the lack of an explicit permissions block will mean different things if the reusable workflow has both workflow_call and other triggers.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@userdocs
Comment options

Answer selected by woodruffw
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants