diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 99465c6..7332a6f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -15,25 +15,18 @@ jobs: steps: - uses: actions/checkout@v4 - - uses: actions/create-github-app-token@v1 - id: app-token - with: - app-id: ${{ vars.RIOTBYTE_BOT_APP_ID }} - private-key: ${{ secrets.RIOTBYTE_BOT_PRIVATE_KEY }} - owner: ${{ github.repository_owner }} - # Empty repositories list = installation-wide access. Without - # this, the token is scoped to the current repo only and 403s - # when fetching packages from sibling repos (project-q, - # nest-service-locator, ...). - repositories: "" - - uses: docker/setup-qemu-action@v3 - uses: docker/setup-buildx-action@v3 - name: Build and push images env: VERSION: ${{ github.ref_name }} - # Default GITHUB_TOKEN cannot read cross-repo packages from - # GHCR npm registry; the App token can (granted org-wide). - GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} + # Default GITHUB_TOKEN works for both GHCR push (packages: write + # granted above) and pnpm install of @riotbyte-com/* internal + # packages (org-internal visibility grants read to repos in the + # same org). Used to use a GitHub App token here but the App's + # packages:read access was misconfigured and PR #10's CI proved + # the default token sufficient. Revisit if the App is fixed up + # and we want consistent token handling across all workflows. + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: ./ci/build-images.sh