fix(ci): grant workflows permission for internal sync push

The sync syncs files under .github/workflows/, which GitHub refuses to
push from a GitHub App token that lacks the workflows permission. Add
permission-workflows: write to the scoped app token.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Samuel Newman
2026-06-29 15:24:12 +03:00
parent 257a11d498
commit 68dffbb322
+4 -1
View File
@@ -28,8 +28,11 @@ jobs:
private-key: ${{ secrets.SYNC_INTERNAL_PK }}
repositories: social-app-internal
# Scope the token down from the app's full installation permissions;
# pushing is the only thing this token is used for
# pushing is the only thing this token is used for. The workflows
# permission is required because the sync includes files under
# .github/workflows/, which GitHub refuses to push without it.
permission-contents: write
permission-workflows: write
- name: Push to internal repo
env:
TOKEN: ${{ steps.app-token.outputs.token }}