feat: grant Dependabot alerts read/write to auto-created GitHub Apps (#543)

## What

Adds the `vulnerability_alerts: write` fine-grained permission to the
GitHub App manifest used when Fabro auto-creates a GitHub App, in
**both** install flows:

- `lib/crates/fabro-server/src/install.rs` (web-UI install)
- `lib/crates/fabro-cli/src/commands/install.rs` (CLI install)

`write` on `vulnerability_alerts` grants both read and write of
Dependabot alerts (write implies read for fine-grained permissions).

The two manifest builders are byte-for-byte identical by design, so both
are updated together. A test assertion in the CLI install tests guards
the new permission.

## Why

We need auto-created Fabro apps to be able to read and manage Dependabot
alerts.

## Note on rollout

Manifest `default_permissions` are applied at **app-creation time**, so
this only affects **newly** auto-created apps. Any app already created
won't pick this up automatically — the owner must add the permission in
the app's settings, and each existing installation must approve the new
permission request.

## Test

- `cargo nextest run -p fabro-cli --
manifest_includes_callback_urls_and_setup_url` passes.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Scott Werner 2026-07-01 18:05:25 -04:00 • committed by GitHub
parent bb369181b6
commit 3e0db1febf
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
2 changed files with 8 additions and 2 deletions

View file

@ -948,7 +948,8 @@ fn build_github_app_manifest(app_name: &str, port: u16, web_url: &str) -> serde_
"pull_requests": "write",
"checks": "write",
"issues": "write",
"emails": "read"
"emails": "read",
"vulnerability_alerts": "write"
},
"default_events": []
})
@ -2662,6 +2663,10 @@ client_id = "client-id"
manifest["setup_url"],
serde_json::json!("https://app.example.com/setup"),
);
assert_eq!(
manifest["default_permissions"]["vulnerability_alerts"],
serde_json::json!("write"),
);
}
#[tokio::test]

View file

@ -2053,7 +2053,8 @@ fn build_github_app_manifest(
"pull_requests": "write",
"checks": "write",
"issues": "write",
"emails": "read"
"emails": "read",
"vulnerability_alerts": "write"
},
"default_events": []
})