Make Actions token permissions explicit

The automatic job token creates the desktop release, so the CD desktop job
asks for contents: write; the images job keeps contents: read and asks for
packages: write so the job token can stand in for the scoped registry PAT.
CI stays read-only. The registry token itself remains a write:package-only
PAT (verified login + pull).
This commit is contained in:
2026-09-22 23:30:37 -05:00
parent 8f9656ac0e
commit ed6178d12e
2 changed files with 16 additions and 2 deletions
+11 -2
View File
@@ -36,9 +36,14 @@ jobs:
images:
name: Build & push images
runs-on: ubuntu-latest
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write`
# also lets the automatic job token stand in when that secret is absent.
permissions:
contents: read
packages: write
env:
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
steps:
- uses: actions/checkout@v4
@@ -59,6 +64,10 @@ jobs:
desktop:
name: Desktop release
runs-on: ubuntu-latest
# Creating the release and uploading its assets uses the automatic job
# token, so it needs write access to the repository's releases.
permissions:
contents: write
steps:
- uses: actions/checkout@v4
@@ -89,7 +98,7 @@ jobs:
- name: Add the Gitea release
env:
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
run: |
set -euo pipefail
VERSION="$(node -p "require('./desktop/package.json').version")"