release/1.0.6 #28

Merged
notazof merged 24 commits from release/1.0.6 into main 2026-08-18 01:02:44 +01:00
Showing only changes of commit c5c4d6b59a - Show all commits

Merge pull request 'ci(forgejo): use runner-provided GITHUB_TOKEN for release workflow' (#23) from fix/forgejo-release-use-runner-token into release/1.0.6

Reviewed-on: #23
Paul Schneider 2026-08-17 01:25:13 +01:00

View file

@ -6,10 +6,14 @@
# publishes a Forgejo release via rasterstate/forgejo-release-action and # publishes a Forgejo release via rasterstate/forgejo-release-action and
# uploads the APK as an asset. # uploads the APK as an asset.
# #
# Authentication uses ${{ secrets.RELEASE_TOKEN }}, a Forgejo PAT scoped # Authentication uses ${{ secrets.GITHUB_TOKEN }} (auto-provided by the
# to `write:repository` configured in the repository's Actions secrets. # Forgejo runner, scoped to contents: write for the current repo). A
# The runner-provided ${{ secrets.GITHUB_TOKEN }} would also work, but # dedicated PAT (${{ secrets.RELEASE_TOKEN }}) was the preferred option
# a dedicated PAT is preferred for least-privilege and revocability. # for least-privilege, but creating repo-level secrets is currently
# broken on this Forgejo instance (InsertEncryptedSecret fails with a
# UTF-8 byte-sequence error, probably a text-vs-bytea column type on
# the secret table). Bumping to Forgejo v16 should fix it; until then,
# the runner-provided token keeps the workflow operational.
# #
# This workflow complements .github/workflows/docker-publish-android.yml # This workflow complements .github/workflows/docker-publish-android.yml
# which targets the GitHub mirror; the validate-release logic mirrors # which targets the GitHub mirror; the validate-release logic mirrors
@ -224,4 +228,4 @@ jobs:
files: | files: |
PostIt.Android.apk PostIt.Android.apk
env: env:
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }} GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}