The ComPWA/action/clean-caches action currently does not have sufficient rights to clean caches for PR from a fork, see for example this log. Compare to this run, which was triggered after a PR from a branch.
Tracked by #186. Related: #185 proposes an organization-owned app, but cache cleanup does not need to wait for it or for #184. A trusted workflow triggered by closure of a fork PR can use the built-in token with Actions write permission, without checking out or executing PR code. Update the corresponding generated workflow in ComPWA/policy as part of the fix so regeneration preserves the behavior.
The
ComPWA/action/clean-cachesaction currently does not have sufficient rights to clean caches for PR from a fork, see for example this log. Compare to this run, which was triggered after a PR from a branch.Tracked by #186. Related: #185 proposes an organization-owned app, but cache cleanup does not need to wait for it or for #184. A trusted workflow triggered by closure of a fork PR can use the built-in token with Actions write permission, without checking out or executing PR code. Update the corresponding generated workflow in ComPWA/policy as part of the fix so regeneration preserves the behavior.