Skip to content

Commit fc4026a

Browse files
chore(runway): cherry-pick fix: cp-7.78.0 add correct permissions to running perf builds (#30224)
- fix: cp-7.78.0 add correct permissions to running perf builds (#30223) <!-- Please submit this PR as a draft initially. Do not mark it as "Ready for review" until this PR meets the canonical Definition of Ready For Review in `docs/readme/ready-for-review.md`. In short: the template must be materially complete (not just section titles present), all status checks must be currently passing, and the only expected follow-up commits must be reviewer-driven. --> ## **Description** > Updates the `run-performance-e2e-experimental.yml` and `run-performance-e2e-release.yml` GitHub Actions workflows to grant `permissions.contents: write` (instead of read-only) so they are at least as permissive as the reusable `run-performance-e2e.yml` workflow they call. > > Adds an inline comment documenting the transitive requirement (via the BrowserStack upload workflows). > ## **Changelog** <!-- If this PR is not End-User-Facing and should not show up in the CHANGELOG, you can choose to either: 1. Write `CHANGELOG entry: null` 2. Label with `no-changelog` If this PR is End-User-Facing, please write a short User-Facing description in the past tense like: `CHANGELOG entry: Added a new tab for users to see their NFTs` `CHANGELOG entry: Fixed a bug that was causing some NFTs to flicker` (This helps the Release Engineer do their job more quickly and accurately) --> CHANGELOG entry: ## **Related issues** Fixes: ## **Manual testing steps** ```gherkin Feature: my feature name Scenario: user [verb for user action] Given [describe expected initial app state] When user [verb for user action] Then [describe expected outcome] ``` ## **Screenshots/Recordings** <!-- If applicable, add screenshots and/or recordings to visualize the before and after of your change. --> ### **Before** <!-- [screenshots/recordings] --> ### **After** <!-- [screenshots/recordings] --> ## **Pre-merge author checklist** <!-- Every checklist item must be consciously assessed before marking this PR as "Ready for review". A checked box means you deliberately considered that responsibility, not that you literally performed every action listed. Unchecked boxes are ambiguous: they are not an implicit "N/A" and they are not a silent "skip". See `docs/readme/ready-for-review.md` for the full checklist semantics. --> - [ ] I've followed [MetaMask Contributor Docs](https://github.com/MetaMask/contributor-docs) and [MetaMask Mobile Coding Standards](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/CODING_GUIDELINES.md). - [ ] I've completed the PR template to the best of my ability - [ ] I've included tests if applicable - [ ] I've documented my code using [JSDoc](https://jsdoc.app/) format if applicable - [ ] I've applied the right labels on the PR (see [labeling guidelines](https://github.com/MetaMask/metamask-mobile/blob/main/.github/guidelines/LABELING_GUIDELINES.md)). Not required for external contributors. #### Performance checks (if applicable) - [ ] I've tested on Android - Ideally on a mid-range device; emulator is acceptable - [ ] I've tested with a power user scenario - Use these [power-user SRPs](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/edit-v2/401401446401?draftShareId=9d77e1e1-4bdc-4be1-9ebb-ccd916988d93) to import wallets with many accounts and tokens - [ ] I've instrumented key operations with Sentry traces for production performance metrics - See [`trace()`](/app/util/trace.ts) for usage and [`addToken`](/app/components/Views/AddAsset/components/AddCustomToken/AddCustomToken.tsx#L274) for an example For performance guidelines and tooling, see the [Performance Guide](https://consensyssoftware.atlassian.net/wiki/spaces/TL1/pages/400085549067/Performance+Guide+for+Engineers). ## **Pre-merge reviewer checklist** <!-- Reviewer checklist items follow the same semantics as the author checklist: an unchecked box is ambiguous, a checked box means the reviewer consciously assessed that responsibility. See `docs/readme/ready-for-review.md`. --> - [ ] I've manually tested the PR (e.g. pull and build branch, run the app, test code being changed). - [ ] I confirm that this PR addresses all acceptance criteria described in the ticket it closes and includes the necessary testing evidence such as recordings and or screenshots. <!-- CURSOR_SUMMARY --> --- > [!NOTE] > **Low Risk** > Low risk workflow-only change that broadens GitHub token permissions to match the called reusable workflow; main risk is over-permissioning if not actually required. > > **Overview** > Updates the `run-performance-e2e-experimental.yml` and `run-performance-e2e-release.yml` GitHub Actions workflows to grant `permissions.contents: write` (instead of read-only) so they are at least as permissive as the reusable `run-performance-e2e.yml` workflow they call. > > Adds an inline comment documenting the transitive requirement (via the BrowserStack upload workflows). > > <sup>Reviewed by [Cursor Bugbot](https://cursor.com/bugbot) for commit 54b2260. Bugbot is set up for automated code reviews on this repo. Configure [here](https://www.cursor.com/dashboard/bugbot).</sup> <!-- /CURSOR_SUMMARY --> [8fbb9a4](8fbb9a4) Co-authored-by: Curtis David <Curtis.David7@gmail.com>
1 parent f8af913 commit fc4026a

2 files changed

Lines changed: 6 additions & 3 deletions

File tree

.github/workflows/run-performance-e2e-experimental.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,8 +18,10 @@ on:
1818
branches:
1919
- main
2020

21+
# Must be at least as permissive as the called reusable workflow (run-performance-e2e.yml),
22+
# which transitively requires contents: write via build-{android,ios}-upload-to-browserstack.yml.
2123
permissions:
22-
contents: read
24+
contents: write
2325
id-token: write
2426
actions: write
2527

.github/workflows/run-performance-e2e-release.yml

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,10 @@ on:
1616
branches:
1717
- 'release/*'
1818

19-
# Required so the reusable workflow run-performance-e2e.yml can use id-token and actions
19+
# Must be at least as permissive as the called reusable workflow (run-performance-e2e.yml),
20+
# which transitively requires contents: write via build-{android,ios}-upload-to-browserstack.yml.
2021
permissions:
21-
contents: read
22+
contents: write
2223
id-token: write
2324
actions: write
2425

0 commit comments

Comments
 (0)