Skip to content

Commit d851106

Browse files
Add policy to allow reading tokens. (#3690)
1 parent 83c21a7 commit d851106

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

.github/chainguard/self.github.pre-commit.pull-requests.sts.yaml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,9 @@ subject: repo:DataDog/datadog-api-client-java:pull_request
66

77
claim_pattern:
88
event_name: pull_request
9-
# Even when running pull_request, the workflow code comes from the base branch, hence refs/heads/master
10-
job_workflow_ref: DataDog/datadog-api-client-java/\.github/workflows/reusable-pre-commit\.yml@refs/heads/master
9+
job_workflow_ref: DataDog/datadog-api-client-java/\.github/workflows/reusable-pre-commit\.yml@refs/pull/[0-9]+/merge
10+
ref: refs/pull/[0-9]+/merge
1111
repository: DataDog/datadog-api-client-java
12-
ref: refs/heads/master
1312

1413
permissions:
1514
contents: write # Required for pushing pre-commit fixes

0 commit comments

Comments
 (0)