diff --git a/.gitea/workflows/cd.yml b/.gitea/workflows/cd.yml index 2f8fd57..cc6ab18 100644 --- a/.gitea/workflows/cd.yml +++ b/.gitea/workflows/cd.yml @@ -36,9 +36,14 @@ jobs: images: name: Build & push images runs-on: ubuntu-latest + # Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write` + # also lets the automatic job token stand in when that secret is absent. + permissions: + contents: read + packages: write env: REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }} - REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }} + REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }} PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }} steps: - uses: actions/checkout@v4 @@ -59,6 +64,10 @@ jobs: desktop: name: Desktop release runs-on: ubuntu-latest + # Creating the release and uploading its assets uses the automatic job + # token, so it needs write access to the repository's releases. + permissions: + contents: write steps: - uses: actions/checkout@v4 @@ -89,7 +98,7 @@ jobs: - name: Add the Gitea release env: - GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }} run: | set -euo pipefail VERSION="$(node -p "require('./desktop/package.json').version")" diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index ff4b560..3ae69a3 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -6,6 +6,11 @@ name: CI +# Tests and builds only need to read the repository; the automatic job token +# stays read-only. +permissions: + contents: read + on: push: branches: ["**"]