mirror of
https://github.com/ppy/osu.git
synced 2026-05-16 23:03:28 +08:00
f9e863af01
[It still doesn't work.](https://github.com/ppy/osu/actions/runs/22759488243/job/66012293202) Looking at the [job output](https://github.com/ppy/osu/actions/runs/22759488243/job/66012293202#step:1:21) it appears that the permissions of the `GITHUB_TOKEN` are *automatically* constrained to `read` even if you request more scopes. Would be nice if that was *actually documented* somewhere! Also given supply-chain attacks that people are running on github [via *issue titles* these days](https://grith.ai/blog/clinejection-when-your-ai-tool-installs-another) I'm not sure we want any automation near where it can reach code. Sure, much of the fault in the aforementioned attack was the fault of meatbags trusting clankers *WAY* too much, which is a mistake we *would not* do, but given everpresent software degradation *from unknown sources and for unknown reasons* let's not ~~COPILOT~~ *ahem* tempt fate...
f9e863af01
·
2026-03-06 19:54:44 +09:00
History