summaryrefslogtreecommitdiff
path: root/docs/_static/css/code-snippets.css
diff options
context:
space:
mode:
authorYuriy Andamasov <yuriy@vyos.io>2026-05-11 11:13:26 +0300
committerYuriy Andamasov <yuriy@vyos.io>2026-05-11 11:13:26 +0300
commit8cf095bca659a9a115b6eb44bac82c2eded83ac6 (patch)
treecfdecd7aec0f02a665fb7f373522036ffb74c92c /docs/_static/css/code-snippets.css
parent54b3589d96dae132321da85aec03bb6c90f67493 (diff)
downloadvyos-documentation-8cf095bca659a9a115b6eb44bac82c2eded83ac6.tar.gz
vyos-documentation-8cf095bca659a9a115b6eb44bac82c2eded83ac6.zip
ci(ai-validation): restore id-token: write (claude-code-action@v1 uses OIDC)
Revert of the id-token drop from #1969. Smoke verify on PR #1977 (empty-commit retrigger run 25658256103) failed at the Pass 2 step: Action failed with error: Could not fetch an OIDC token. Did you remember to add `id-token: write` to your workflow permissions? The earlier Copilot finding that motivated dropping the permission ("no step uses OIDC") was incomplete. No shell step in the workflow invokes OIDC directly, but anthropics/claude-code-action@v1 itself calls actions/core's `getIDToken()` internally — likely for the Claude/Anthropic auth federation path. The required scope is the third-party action's, not the workflow body's. Adding id-token: write back with an inline comment block citing the specific failure mode + the run ID where it was reproduced so this isn't re-dropped on a future review pass. Mirrored byte-identically across rolling/circinus/sagitta + canonical.
Diffstat (limited to 'docs/_static/css/code-snippets.css')
0 files changed, 0 insertions, 0 deletions