INNER CODE UNIT · Go

ciIsolationStepIndex

minekube/gate · ci_write_token_isolation_test.go:90

func ciIsolationStepIndex(steps []ciIsolationWorkflowStep, name string) int {
	for i, step := range steps {
		if step.Name == name {
			return i
		}
	}
	return -1
}

func TestCIGrantsNoAmbientWritePermission(t *testing.T) {
	workflow, _ := readCIIsolationWorkflow(t)
	if len(workflow.Permissions) != 0 {
		t.Fatalf("workflow permissions are %v; ci.yml must have no ambient token grant", workflow.Permissions)
	}

	// pinned-tools runs the pinned-tool toolchain guard
	// (.github/scripts/check-pinned-go-tools.sh): checkout without persisted
	// credentials + contents: read only, like the other code-running jobs.

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…