Skip to content

Fix dd-octo-sts policy name for dd-trace-rb consumer - #111

Merged
TonyCTHsu merged 2 commits into
mainfrom
fix/dd-octo-sts-policy-name
Aug 6, 2026
Merged

Fix dd-octo-sts policy name for dd-trace-rb consumer#111
TonyCTHsu merged 2 commits into
mainfrom
fix/dd-octo-sts-policy-name

Conversation

@TonyCTHsu

@TonyCTHsu TonyCTHsu commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

Summary

Test plan

  • Merge alongside the companion PR
  • Re-run Notify Consumers and confirm the dispatch succeeds

The matrix entry referenced images-rb.notify-dd-trace-rb, but the policy
argument is resolved against the target repo's trust policy files, not
the caller. Points at dd-trace-rb's new images-rb.notify-consumers
policy (.github/chainguard/images-rb.notify-consumers.sts.yaml), which
names this workflow as caller -- distinct from dd-trace-rb's own
self.update-images policy used by its update-images.yml to open the
pin PR. Previously every dispatch failed with "no application matches
the requested scope".
@TonyCTHsu
TonyCTHsu merged commit 809437d into main Aug 6, 2026
6 checks passed
@TonyCTHsu
TonyCTHsu deleted the fix/dd-octo-sts-policy-name branch August 6, 2026 07:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants