From df812649b6343d3d4e90325d993c607fca449e2f Mon Sep 17 00:00:00 2001 From: 4gray Date: Sat, 18 Jul 2026 16:28:39 +0200 Subject: [PATCH] ci(release): grant actions:write so PR-close cleanup can cancel builds gh run cancel needs the actions scope; with only contents: write the cancellation 403s silently and the settle-poll burns its full window. Also skip the cleanup job for fork PRs entirely: they never get a draft and their token is read-only regardless of the permissions block. Addresses Greptile P1 / Codex P2 follow-up on #1202. Co-Authored-By: Claude Fable 5 --- .github/workflows/cleanup-pr-draft.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/cleanup-pr-draft.yml b/.github/workflows/cleanup-pr-draft.yml index aca2db6f6..6123778f5 100644 --- a/.github/workflows/cleanup-pr-draft.yml +++ b/.github/workflows/cleanup-pr-draft.yml @@ -4,12 +4,19 @@ on: pull_request: types: [closed] +# contents: write — delete the draft release; actions: write — cancel the +# closed PR's still-running build workflow before deleting. permissions: + actions: write contents: write jobs: delete-draft: name: Delete PR draft release + # Fork PRs never get a draft (the release job skips them) and their + # GITHUB_TOKEN is read-only regardless of the permissions block, so + # there is nothing to cancel or delete. + if: github.event.pull_request.head.repo.full_name == github.repository runs-on: ubuntu-latest steps: # A build for this PR may still be running and would recreate the