From 0c06bdde2b75be153a2389fea166943b895d7d36 Mon Sep 17 00:00:00 2001 From: Hamish Fagg Date: Tue, 29 Sep 2026 14:29:05 +1300 Subject: [PATCH] Give the PR environment prune token Administration write The first real run got HTTP 403 on every environment delete with a token holding Environments write. The release-train installation already has Administration write; the token was downscoped past it. Co-Authored-By: Claude Opus 5.5 --- .github/workflows/prune-pr-environments.yml | 2 ++ 1 file changed, 2 insertions(+) diff --git a/.github/workflows/prune-pr-environments.yml b/.github/workflows/prune-pr-environments.yml index 5a6c243..e2fa80c 100644 --- a/.github/workflows/prune-pr-environments.yml +++ b/.github/workflows/prune-pr-environments.yml @@ -42,7 +42,9 @@ jobs: private-key: ${{ secrets.RELEASE_APP_PRIVATE_KEY }} owner: ${{ github.repository_owner }} repositories: ${{ env.ANCHOR_REPOS }} + # Deleting an environment is refused with Environments write alone. permission-actions: read + permission-administration: write permission-environments: write permission-pull-requests: read