INNER CODE UNIT · Go
ciIsolationStepIndex
minekube/gate · ci_write_token_isolation_test.go:90
func ciIsolationStepIndex(steps []ciIsolationWorkflowStep, name string) int {
for i, step := range steps {
if step.Name == name {
return i
}
}
return -1
}
func TestCIGrantsNoAmbientWritePermission(t *testing.T) {
workflow, _ := readCIIsolationWorkflow(t)
if len(workflow.Permissions) != 0 {
t.Fatalf("workflow permissions are %v; ci.yml must have no ambient token grant", workflow.Permissions)
}
// pinned-tools runs the pinned-tool toolchain guard
// (.github/scripts/check-pinned-go-tools.sh): checkout without persisted
// credentials + contents: read only, like the other code-running jobs.