Release Tag still authenticates GoReleaser with secrets.RELEASE_TOKEN, a legacy PAT that CI policy no longer wants refreshed. Prefer the job built-in token with contents: write, mirror it into GITHUB_TOKEN the way vulture does, and force GoReleaser onto the Gitea token path. Link: #11
This commit is contained in:
@@ -7,6 +7,8 @@ on:
|
||||
jobs:
|
||||
release:
|
||||
runs-on: ubuntu-latest
|
||||
permissions:
|
||||
contents: write
|
||||
steps:
|
||||
- uses: actions/checkout@main
|
||||
with:
|
||||
@@ -21,4 +23,7 @@ jobs:
|
||||
version: 'latest'
|
||||
args: release
|
||||
env:
|
||||
GITEA_TOKEN: ${{secrets.RELEASE_TOKEN}}
|
||||
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
# Prefer Gitea when the runner also injects GITHUB_TOKEN.
|
||||
GITHUB_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
GORELEASER_FORCE_TOKEN: gitea
|
||||
|
||||
Reference in New Issue
Block a user