Skip to content

Update merge-gatekeeper action and add actions permission#2014

Merged
azu merged 1 commit into
masterfrom
claude/update-merge-gatekeeper-37xjB
Apr 26, 2026
Merged

Update merge-gatekeeper action and add actions permission#2014
azu merged 1 commit into
masterfrom
claude/update-merge-gatekeeper-37xjB

Conversation

@azu

@azu azu commented Apr 26, 2026

Copy link
Copy Markdown
Member

Summary

Updated the merge-gatekeeper GitHub Action to use a different source repository and version, while also adding the actions: read permission to the workflow job.

Key Changes

  • Changed merge-gatekeeper action source from upsidr/merge-gatekeeper to starkware-libs/merge-gatekeeper
  • Updated action version from v1.2.1 to v1.1.0 (commit 90b067dac75b94c354c3f47a0462d126eae40413)
  • Added actions: read permission to the job's permission scope

Details

The workflow now uses the StarkWare Labs maintained version of the merge-gatekeeper action instead of the previous source. The addition of the actions: read permission aligns with the principle of least privilege by explicitly declaring the minimal permissions required for the job to function properly.

https://claude.ai/code/session_01CeFbyjzYb5h46EGm11zFsm

…keeper v1.1.0

The upsidr/merge-gatekeeper repository is no longer maintained.
Switch to the actively maintained starkware-libs fork at v1.1.0,
which adds 'actions: read' permission required for superseded
workflow run detection.

Co-authored-by: azu <azu@users.noreply.github.com>
Copilot AI review requested due to automatic review settings April 26, 2026 13:08

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ Devin Review: No Issues Found

Devin Review analyzed this PR and found no potential bugs to report.

View in Devin Review to see 1 additional finding.

Open in Devin Review

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s Merge Gatekeeper workflow to use the StarkWare-maintained merge-gatekeeper action and explicitly grants the workflow job actions: read permissions.

Changes:

  • Switch uses: from upsidr/merge-gatekeeper to starkware-libs/merge-gatekeeper (pinned to a specific commit).
  • Add actions: read to the job’s permissions block.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@azu azu added the Type: CI Changes to CI configuration files and scripts label Apr 26, 2026
@azu azu merged commit 901abea into master Apr 26, 2026
26 checks passed
@azu azu deleted the claude/update-merge-gatekeeper-37xjB branch April 26, 2026 13:22
@github-actions github-actions Bot mentioned this pull request Apr 26, 2026
azu added a commit that referenced this pull request Apr 26, 2026
<!-- Release notes generated using configuration in .github/release.yml
at master -->

## What's Changed
### Features
* feat(markdown-to-ast): add support for TOML and JSON frontmatter by
@3w36zj6 in #2012
### CI
* fix(ci): remove CNAME from website PR preview build by @azu in
#1999
* chore(deps): update github/codeql-action action to v3.35.2 by
@renovate[bot] in #2010
* Update merge-gatekeeper action and add actions permission by @azu in
#2014
### Dependency Updates
* chore(deps): update docusaurus monorepo to ^3.10.0 (minor) by
@renovate[bot] in #2000
* chore(deps): update dependency oxlint to ^1.59.0 by @renovate[bot] in
#2002
* chore(deps): update patch updates (patch) by @renovate[bot] in
#2001
* chore(deps): update dependency oxlint-tsgolint to ^0.20.0 by
@renovate[bot] in #2004
* chore(deps): update dependency json5 to ^2.2.3 by @renovate[bot] in
#2003
* chore(deps): update react monorepo to ^19.2.5 (patch) by
@renovate[bot] in #2005
* chore(deps): update dependency oxlint-tsgolint to ^0.21.0 by
@renovate[bot] in #2007
* chore(deps): update dependency oxlint-tsgolint to ^0.21.1 by
@renovate[bot] in #2009
* chore(deps): update pnpm to v10.33.1 by @renovate[bot] in
#2011
* chore(deps): update pnpm to v10.33.2 by @renovate[bot] in
#2013
### Other Changes
* fix(website): move onBrokenMarkdownLinks into markdown.hooks by @azu
in #1998


**Full Changelog**:
v15.5.4...v15.6.0

Co-authored-by: azu <azu@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Type: CI Changes to CI configuration files and scripts

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants