Make Actions token permissions explicit
The automatic job token creates the desktop release, so the CD desktop job asks for contents: write; the images job keeps contents: read and asks for packages: write so the job token can stand in for the scoped registry PAT. CI stays read-only. The registry token itself remains a write:package-only PAT (verified login + pull).
This commit is contained in:
+11
-2
@@ -36,9 +36,14 @@ jobs:
|
||||
images:
|
||||
name: Build & push images
|
||||
runs-on: ubuntu-latest
|
||||
# Registry pushes use the scoped REGISTRY_TOKEN secret; `packages: write`
|
||||
# also lets the automatic job token stand in when that secret is absent.
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write
|
||||
env:
|
||||
REGISTRY_USER: ${{ secrets.REGISTRY_USER || github.actor }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITHUB_TOKEN }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN || secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
@@ -59,6 +64,10 @@ jobs:
|
||||
desktop:
|
||||
name: Desktop release
|
||||
runs-on: ubuntu-latest
|
||||
# Creating the release and uploading its assets uses the automatic job
|
||||
# token, so it needs write access to the repository's releases.
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
@@ -89,7 +98,7 @@ jobs:
|
||||
|
||||
- name: Add the Gitea release
|
||||
env:
|
||||
GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||
run: |
|
||||
set -euo pipefail
|
||||
VERSION="$(node -p "require('./desktop/package.json').version")"
|
||||
|
||||
@@ -6,6 +6,11 @@
|
||||
|
||||
name: CI
|
||||
|
||||
# Tests and builds only need to read the repository; the automatic job token
|
||||
# stays read-only.
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ["**"]
|
||||
|
||||
Reference in New Issue
Block a user