release/1.0.6 #28

Merged
notazof merged 24 commits from release/1.0.6 into main 2026-08-18 01:02:44 +01:00
Showing only changes of commit 80cb8c46fc - Show all commits

ci(forgejo): use runner-provided GITHUB_TOKEN for release workflow

Repo-level secrets creation is broken on this Forgejo instance
(InsertEncryptedSecret fails with UTF-8 byte-sequence error, likely
a text-vs-bytea column type on the secret table). The fix is in
upstream Forgejo v16; until then, ${{ secrets.GITHUB_TOKEN }} (auto-
provided by the runner, scoped to contents: write for the current
repo) keeps the release workflow operational without any UI setup.

When the instance is upgraded and the secret table is migrated,
revert this commit to switch back to ${{ secrets.RELEASE_TOKEN }}
for least-privilege.
Paul Schneider 2026-08-17 01:23:44 +01:00
Signed by: notazof
GPG key ID: 1DD5D838E5343B06

View file

@ -6,10 +6,14 @@
# publishes a Forgejo release via rasterstate/forgejo-release-action and
# uploads the APK as an asset.
#
# Authentication uses ${{ secrets.RELEASE_TOKEN }}, a Forgejo PAT scoped
# to `write:repository` configured in the repository's Actions secrets.
# The runner-provided ${{ secrets.GITHUB_TOKEN }} would also work, but
# a dedicated PAT is preferred for least-privilege and revocability.
# Authentication uses ${{ secrets.GITHUB_TOKEN }} (auto-provided by the
# Forgejo runner, scoped to contents: write for the current repo). A
# dedicated PAT (${{ secrets.RELEASE_TOKEN }}) was the preferred option
# for least-privilege, but creating repo-level secrets is currently
# broken on this Forgejo instance (InsertEncryptedSecret fails with a
# UTF-8 byte-sequence error, probably a text-vs-bytea column type on
# the secret table). Bumping to Forgejo v16 should fix it; until then,
# the runner-provided token keeps the workflow operational.
#
# This workflow complements .github/workflows/docker-publish-android.yml
# which targets the GitHub mirror; the validate-release logic mirrors
@ -224,4 +228,4 @@ jobs:
files: |
PostIt.Android.apk
env:
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }}
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}