From b38870847416ba87e2e7343e7b5fbc02b49f2c85 Mon Sep 17 00:00:00 2001 From: Frank Elsinga Date: Wed, 14 Jan 2026 14:15:20 +0100 Subject: [PATCH] fix more zizmor findings --- .../workflows/mark-as-draft-on-requesting-changes.yml | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/.github/workflows/mark-as-draft-on-requesting-changes.yml b/.github/workflows/mark-as-draft-on-requesting-changes.yml index 0d6bdc3d3..92efb2899 100644 --- a/.github/workflows/mark-as-draft-on-requesting-changes.yml +++ b/.github/workflows/mark-as-draft-on-requesting-changes.yml @@ -12,13 +12,13 @@ on: # zizmor: ignore[dangerous-triggers] - labeled - ready_for_review -permissions: - pull-requests: write - issues: write +permissions: {} jobs: mark-draft: runs-on: ubuntu-latest + permissions: + pull-requests: write if: | ( github.event.action == 'review_submitted' && @@ -41,10 +41,12 @@ jobs: env: GH_TOKEN: ${{ github.token }} run: | - gh pr ready "${{ github.event.pull_request.html_url }}" --undo || true + gh pr ready "${{ github.event.pull_request.number }}" --undo || true ready-for-review: runs-on: ubuntu-latest + permissions: + pull-requests: write if: github.event.action == 'ready_for_review' steps: - name: Update labels for review