Skip to content

merge queue: queuing main (964a793) and #11827 together#11834

Closed
mergify[bot] wants to merge 2 commits into
mainfrom
mergify/merge-queue/76cc2a64cb
Closed

merge queue: queuing main (964a793) and #11827 together#11834
mergify[bot] wants to merge 2 commits into
mainfrom
mergify/merge-queue/76cc2a64cb

Conversation

@mergify

@mergify mergify Bot commented Jun 15, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request has been checked successfully and will be merged soon. 🎉

Branch main (964a793) and #11827 are queued together for merge.

This pull request has been created by Mergify to check the mergeability of #11827.
You don't need to do anything. Mergify will close this pull request automatically when it is complete.

Required conditions of queue rule default for merge:

Required conditions to stay in the queue:

---
checking_base_sha: 964a793516b77c8804e09bf836ba75284ce211d5
previous_failed_batches: []
pull_requests:
  - number: 11827
    scopes: []
scopes: []
...

sileht and others added 2 commits June 14, 2026 18:17
Per-repository product enablement, including activating CI Insights, is
enforced at repository WRITE level via PUT /v1/products/{owner}/{repository}.
Only the org-level default-products configuration requires Integrations Admin.

Correct the security page so the documented model matches enforcement:
- Features Permissions: "Activate CI Insights on a repository" is write-level,
  not Owner-only.
- Delegated Roles: Integrations Admin grants org-level default products and
  third-party integrations, not per-repo product enablement; drop "activate
  CI Insights" from CI Admin since per-repo activation is write-level, not a
  delegated owner power.
- Tighten the Delegated Roles intro so its examples reference org-level
  operations only.

Surfaced by HackerOne #3801915: a write collaborator activated CI Insights
and the reporter cited these rows as the owner-only boundary. The docs were
wrong; the access-control behavior is correct.

Fixes MRGFY-7644

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Change-Id: I90961aa435b34f468fec7921b6664bee5199e832
@mergify mergify Bot deployed to Mergify Merge Protections June 15, 2026 07:56 Active
@mergify mergify Bot closed this Jun 15, 2026
@mergify mergify Bot deleted the mergify/merge-queue/76cc2a64cb branch June 15, 2026 07:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant