Authenticate the registry push with a scoped token
build / Build and push image (push) Successful in 1m45s
build / Build and push image (push) Successful in 1m45s
The automatic token is rejected by the package registry regardless of the permissions the job requests, so the push uses a personal access token scoped to package read and write. The job no longer asks for packages: write, since nothing it does with the automatic token touches the registry.
This commit is contained in:
@@ -24,7 +24,6 @@ jobs:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
packages: write # regctl pushes the image to the registry (zizmor)
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
||||
@@ -65,7 +64,7 @@ jobs:
|
||||
TAG: ${{ steps.tag.outputs.value }}
|
||||
REGISTRY_USER: ${{ github.actor }}
|
||||
# zizmor: ignore[secrets-outside-env]
|
||||
REGISTRY_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
||||
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||
run: |
|
||||
printf '%s' "$REGISTRY_TOKEN" |
|
||||
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin
|
||||
|
||||
Reference in New Issue
Block a user