github / github/command

"maintain" cannot be used to verify actor permissions

オープン
#101 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
JavaScript
スター
167
フォーク
17
PR マージ指標
30日以内にマージされた PR はありません

説明

### Describe the Issue

The "maintain" permission cannot be used to to verify the actor permissions. As a user with the "maintain" permission I would expect the following configuration to work. However, a comment is created that I only have the "write" permission.

Reading the GH API docs, it clearly states the "permission" field uses legacy base roles and that "maintain" is mapped to "write" [(ref)](https://docs.github.com/en/rest/collaborators/collaborators?apiVersion=2026-03-10#get-repository-permissions-for-a-user). So the output is expected but it is not clearly stated in this Action's documentation. Furthermore, using this legacy permission field of the API prevents us from differentiating between users with the write and users with the maintain role. In our case, we only want maintainers to be able to use the defined command and not developers with the "write" role.

### Action Configuration

```yaml
steps:
- uses: github/command@v2
id: command
with:
command: "/tf-apply"
permissions: maintain,admin
allowed_contexts: pull_request
reaction: "rocket"
skip_ci: true
```

### Relevant Actions Log Output

```
👋 , seems as if you have not maintain/admin permissions in this repo, permissions: write
```

### Extra Information

_No response_

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

提供された github/command@v2 設定と、示されているログ出力を生成する権限チェックから始めます。GitHub API の権限フィールドを maintain ロールおよび write ロールと比較し、提供された workflow 設定を使って動作を確認します。Done の条件は、maintain ユーザーと write ユーザーを区別できること、または API がその区別をサポートできない場合にその制限が明確に文書化されていることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions, javascript
領域
ci-cd
issue の種類
機能追加
難易度
3/5
見積もり時間
1〜2日
活発さ
静か
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。