The packaging workflow pushed alpha releases to noDRM/DeDRM_tools_autorelease
using secrets.AUTORELEASE_KEY, which only exists on the upstream repo. On a
fork the secret is empty, so the "Delete older auto-releases" step failed with
"no GITHUB_TOKEN found", and even with a token a fork cannot publish into
noDRM's release repo.
Point the release at ${{ github.repository }} and use the built-in
secrets.GITHUB_TOKEN (scoped to the current repo) with contents: write
permission, so each fork publishes its own alpha release with no PAT required.
Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Rename main.yml to release.yml to reflect that it packages the plugin and
publishes the auto-release. Name the job and the previously unnamed step,
strip trailing whitespace, and pin every action to a commit SHA (with a
version comment) at its latest release:
- actions/checkout v2 -> v7.0.0
- actions/upload-artifact v4 -> v7.0.1
- dev-drprasad/delete-older-releases v0.2.1 -> v0.3.4
- softprops/action-gh-release v1 -> v3.0.1
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Run the pytest suite on pull requests to master across Python 3.9, 3.11
and 3.13 (the last exercises the legacy-cgi backport), installing
dependencies with Poetry. Actions are pinned to commit SHAs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>