From 00228f7e8600ce59800541c3eb61d4ec6eb54455 Mon Sep 17 00:00:00 2001 From: Niels Mokkenstorm Date: Wed, 13 May 2026 21:41:31 +0200 Subject: [PATCH] fix(ci): use default GITHUB_TOKEN for release.yml image build --- .github/workflows/release.yml | 23 ++++++++--------------- 1 file changed, 8 insertions(+), 15 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 99465c6..7332a6f 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -15,25 +15,18 @@ jobs: steps: - uses: actions/checkout@v4 - - uses: actions/create-github-app-token@v1 - id: app-token - with: - app-id: ${{ vars.RIOTBYTE_BOT_APP_ID }} - private-key: ${{ secrets.RIOTBYTE_BOT_PRIVATE_KEY }} - owner: ${{ github.repository_owner }} - # Empty repositories list = installation-wide access. Without - # this, the token is scoped to the current repo only and 403s - # when fetching packages from sibling repos (project-q, - # nest-service-locator, ...). - repositories: "" - - uses: docker/setup-qemu-action@v3 - uses: docker/setup-buildx-action@v3 - name: Build and push images env: VERSION: ${{ github.ref_name }} - # Default GITHUB_TOKEN cannot read cross-repo packages from - # GHCR npm registry; the App token can (granted org-wide). - GITHUB_TOKEN: ${{ steps.app-token.outputs.token }} + # Default GITHUB_TOKEN works for both GHCR push (packages: write + # granted above) and pnpm install of @riotbyte-com/* internal + # packages (org-internal visibility grants read to repos in the + # same org). Used to use a GitHub App token here but the App's + # packages:read access was misconfigured and PR #10's CI proved + # the default token sufficient. Revisit if the App is fixed up + # and we want consistent token handling across all workflows. + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} run: ./ci/build-images.sh -- 2.51.2