Authenticate the registry push with a scoped token
build / Build and push image (push) Successful in 1m45s
build / Build and push image (push) Successful in 1m45s
The automatic token is rejected by the package registry regardless of the permissions the job requests, so the push uses a personal access token scoped to package read and write. The job no longer asks for packages: write, since nothing it does with the automatic token touches the registry.
This commit is contained in:
@@ -24,7 +24,6 @@ jobs:
|
|||||||
|
|
||||||
permissions:
|
permissions:
|
||||||
contents: read
|
contents: read
|
||||||
packages: write # regctl pushes the image to the registry (zizmor)
|
|
||||||
|
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
- uses: actions/checkout@11d5960a326750d5838078e36cf38b85af677262 # v4.4.0
|
||||||
@@ -65,7 +64,7 @@ jobs:
|
|||||||
TAG: ${{ steps.tag.outputs.value }}
|
TAG: ${{ steps.tag.outputs.value }}
|
||||||
REGISTRY_USER: ${{ github.actor }}
|
REGISTRY_USER: ${{ github.actor }}
|
||||||
# zizmor: ignore[secrets-outside-env]
|
# zizmor: ignore[secrets-outside-env]
|
||||||
REGISTRY_TOKEN: ${{ secrets.GITEA_TOKEN }}
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
run: |
|
run: |
|
||||||
printf '%s' "$REGISTRY_TOKEN" |
|
printf '%s' "$REGISTRY_TOKEN" |
|
||||||
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin
|
regctl registry login "$REGISTRY" --user "$REGISTRY_USER" --pass-stdin
|
||||||
|
|||||||
Reference in New Issue
Block a user