From 3e0db1febf96c6b814693426db07a7ee85a3c8d2 Mon Sep 17 00:00:00 2001 From: Scott Werner Date: Wed, 1 Jul 2026 18:05:25 -0400 Subject: [PATCH] feat: grant Dependabot alerts read/write to auto-created GitHub Apps (#543) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit ## What Adds the `vulnerability_alerts: write` fine-grained permission to the GitHub App manifest used when Fabro auto-creates a GitHub App, in **both** install flows: - `lib/crates/fabro-server/src/install.rs` (web-UI install) - `lib/crates/fabro-cli/src/commands/install.rs` (CLI install) `write` on `vulnerability_alerts` grants both read and write of Dependabot alerts (write implies read for fine-grained permissions). The two manifest builders are byte-for-byte identical by design, so both are updated together. A test assertion in the CLI install tests guards the new permission. ## Why We need auto-created Fabro apps to be able to read and manage Dependabot alerts. ## Note on rollout Manifest `default_permissions` are applied at **app-creation time**, so this only affects **newly** auto-created apps. Any app already created won't pick this up automatically — the owner must add the permission in the app's settings, and each existing installation must approve the new permission request. ## Test - `cargo nextest run -p fabro-cli -- manifest_includes_callback_urls_and_setup_url` passes. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 4.8 (1M context) --- lib/crates/fabro-cli/src/commands/install.rs | 7 ++++++- lib/crates/fabro-server/src/install.rs | 3 ++- 2 files changed, 8 insertions(+), 2 deletions(-) diff --git a/lib/crates/fabro-cli/src/commands/install.rs b/lib/crates/fabro-cli/src/commands/install.rs index d5c2145e4..b8fabff08 100644 --- a/lib/crates/fabro-cli/src/commands/install.rs +++ b/lib/crates/fabro-cli/src/commands/install.rs @@ -948,7 +948,8 @@ fn build_github_app_manifest(app_name: &str, port: u16, web_url: &str) -> serde_ "pull_requests": "write", "checks": "write", "issues": "write", - "emails": "read" + "emails": "read", + "vulnerability_alerts": "write" }, "default_events": [] }) @@ -2662,6 +2663,10 @@ client_id = "client-id" manifest["setup_url"], serde_json::json!("https://app.example.com/setup"), ); + assert_eq!( + manifest["default_permissions"]["vulnerability_alerts"], + serde_json::json!("write"), + ); } #[tokio::test] diff --git a/lib/crates/fabro-server/src/install.rs b/lib/crates/fabro-server/src/install.rs index aae91785a..6416c340e 100644 --- a/lib/crates/fabro-server/src/install.rs +++ b/lib/crates/fabro-server/src/install.rs @@ -2053,7 +2053,8 @@ fn build_github_app_manifest( "pull_requests": "write", "checks": "write", "issues": "write", - "emails": "read" + "emails": "read", + "vulnerability_alerts": "write" }, "default_events": [] })