Make Actions token permissions explicit
The automatic job token creates the desktop release, so the CD desktop job asks for contents: write; the images job keeps contents: read and asks for packages: write so the job token can stand in for the scoped registry PAT. CI stays read-only. The registry token itself remains a write:package-only PAT (verified login + pull).
This commit is contained in:
+11
-2
@@ -36,9 +36,14 @@ jobs:
|
|||||||
images:
|
images:
|
||||||
name: Build & push images
|
name: Build & push images
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write`
|
||||||
|
# also lets the automatic job token stand in when that secret is absent.
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
packages: write
|
||||||
env:
|
env:
|
||||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
||||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
@@ -59,6 +64,10 @@ jobs:
|
|||||||
desktop:
|
desktop:
|
||||||
name: Desktop release
|
name: Desktop release
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
|
# Creating the release and uploading its assets uses the automatic job
|
||||||
|
# token, so it needs write access to the repository's releases.
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@v4
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
@@ -89,7 +98,7 @@ jobs:
|
|||||||
|
|
||||||
- name: Add the Gitea release
|
- name: Add the Gitea release
|
||||||
env:
|
env:
|
||||||
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
VERSION="$(node -p "require('./desktop/package.json').version")"
|
VERSION="$(node -p "require('./desktop/package.json').version")"
|
||||||
|
|||||||
@@ -6,6 +6,11 @@
|
|||||||
|
|
||||||
name: CI
|
name: CI
|
||||||
|
|
||||||
|
# Tests and builds only need to read the repository; the automatic job token
|
||||||
|
# stays read-only.
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
on:
|
on:
|
||||||
push:
|
push:
|
||||||
branches: ["**"]
|
branches: ["**"]
|
||||||
|
|||||||
Reference in New Issue
Block a user