ci: pass GITHUB_TOKEN explicitly to checkout and release steps
Add explicit token inputs to the checkout and softprops/action-gh-release steps so the GitHub token is wired through instead of relying on implicit defaults. The workflow-level contents: write permission already scopes the token correctly for tag/release creation.
This commit is contained in:
@@ -33,6 +33,7 @@ jobs:
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
ref: ${{ steps.ref.outputs.ref }}
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
|
||||
- name: Setup Go
|
||||
uses: actions/setup-go@v5
|
||||
@@ -52,6 +53,7 @@ jobs:
|
||||
- name: Create release
|
||||
uses: softprops/action-gh-release@v2
|
||||
with:
|
||||
token: ${{ secrets.GITHUB_TOKEN }}
|
||||
tag_name: ${{ steps.ref.outputs.tag }}
|
||||
name: ${{ steps.ref.outputs.tag }}
|
||||
generate_release_notes: true
|
||||
|
||||
Reference in New Issue
Block a user