From 97c973ec268d534ce00107efe57301110477422f Mon Sep 17 00:00:00 2001 From: Wibias <37517432+Wibias@users.noreply.github.com> Date: Thu, 6 Aug 2026 11:23:48 +0200 Subject: [PATCH] test(ci): accept the Copilot permission in the issue-quality workflow pin The issue-quality workflow's translate job migrated from the actions/ai-inference permission (models: read) to the Copilot CLI permission (copilot-requests: write) in 3a7a72d8, but the regression test still pinned models: read. The test was guarding that the job stays job-scoped (no top-level issues:write, no actions:write), so it now accepts either permission name and keeps that guard. --- tests/ci-workflows.test.ts | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/ci-workflows.test.ts b/tests/ci-workflows.test.ts index c5b635d65cd..35e39beab7c 100644 --- a/tests/ci-workflows.test.ts +++ b/tests/ci-workflows.test.ts @@ -4142,7 +4142,7 @@ describe("GitHub Actions hardening", () => { // Job-scoped permissions only (no top-level issues:write; no actions:write). expect(workflow).toMatch( - /jobs:\s*\n\s*translate:[\s\S]*?permissions:\s*\n(?:\s*#.*\n)*\s*contents: read\s*\n(?:\s*#.*\n)*\s*issues: write\s*\n(?:\s*#.*\n)*\s*models: read/, + /jobs:\s*\n\s*translate:[\s\S]*?permissions:\s*\n(?:\s*#.*\n)*\s*contents: read\s*\n(?:\s*#.*\n)*\s*issues: write\s*\n(?:\s*#.*\n)*\s*(?:copilot-requests: write|models: read)/, ); const translateJob = workflow.split(/\n {2}translate:\n/)[1]!.split(/\n {2}[a-zA-Z]/)[0]!; expect(translateJob).not.toMatch(/actions:\s*write/);