Authenticate the registry push with a scoped token
build / Build and push image (push) Successful in 1m45s

The automatic token is rejected by the package registry regardless of the
permissions the job requests, so the push uses a personal access token scoped
to package read and write. The job no longer asks for packages: write, since
nothing it does with the automatic token touches the registry.
This commit is contained in:
2026-07-31 09:02:27 -05:00
parent 5c0a7263e4
commit 2b61c3a639
+1 -2
View File
@@ -24,7 +24,6 @@ jobs:
permissions:
contents: read
packages: write # regctl pushes the image to the registry (zizmor)
steps:
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
@@ -65,7 +64,7 @@ jobs:
TAG: ${{ steps.tag.outputs.value }}
REGISTRY_USER: ${{ github.actor }}
# zizmor: ignore[secrets-outside-env]
REGISTRY_TOKEN: ${{ secrets.GITEA_TOKEN }}
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
run: |
printf '%s' "$REGISTRY_TOKEN" |
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin