Skip to content

Document reusable attestation token scope - #2

Merged
firegrass merged 1 commit into
mainfrom
agent/document-optional-attestation-permission
Aug 3, 2026
Merged

Document reusable attestation token scope#2
firegrass merged 1 commit into
mainfrom
agent/document-optional-attestation-permission

Conversation

@firegrass

Copy link
Copy Markdown
Contributor

What changed

  • document the caller permission required by GitHub's reusable-workflow negotiation
  • show the complete permission block in the Cargo example
  • clarify that disabling derived-image provenance skips the write even though the scope must be granted

Why

The first private canary rerun exposed this GitHub platform nuance as a startup failure before any job was created.

Validation

  • Markdown diff is whitespace-clean
  • the corrected private caller now starts successfully and skips the attestation step

Refs BKLG-20260803-0d11.

Clarifies that GitHub permission negotiation still requires the declared token scope when derived-image provenance publication is disabled.\n\nRefs BKLG-20260803-0d11.
@firegrass
firegrass merged commit 84ff820 into main Aug 3, 2026
1 check passed
@firegrass
firegrass deleted the agent/document-optional-attestation-permission branch August 3, 2026 17:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant