ci: pass GITHUB_TOKEN explicitly to checkout and release steps
Add explicit token inputs to the checkout and softprops/action-gh-release steps so the GitHub token is wired through instead of relying on implicit defaults. The workflow-level contents: write permission already scopes the token correctly for tag/release creation.
This commit is contained in:
@@ -33,6 +33,7 @@ jobs:
|
|||||||
uses: actions/checkout@v4
|
uses: actions/checkout@v4
|
||||||
with:
|
with:
|
||||||
ref: ${{ steps.ref.outputs.ref }}
|
ref: ${{ steps.ref.outputs.ref }}
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
|
|
||||||
- name: Setup Go
|
- name: Setup Go
|
||||||
uses: actions/setup-go@v5
|
uses: actions/setup-go@v5
|
||||||
@@ -52,6 +53,7 @@ jobs:
|
|||||||
- name: Create release
|
- name: Create release
|
||||||
uses: softprops/action-gh-release@v2
|
uses: softprops/action-gh-release@v2
|
||||||
with:
|
with:
|
||||||
|
token: ${{ secrets.GITHUB_TOKEN }}
|
||||||
tag_name: ${{ steps.ref.outputs.tag }}
|
tag_name: ${{ steps.ref.outputs.tag }}
|
||||||
name: ${{ steps.ref.outputs.tag }}
|
name: ${{ steps.ref.outputs.tag }}
|
||||||
generate_release_notes: true
|
generate_release_notes: true
|
||||||
|
|||||||
Reference in New Issue
Block a user