diff --git a/.github/workflows/prepare-publish.yml b/.github/workflows/prepare-publish.yml index 8f60b1b21..13fa02506 100644 --- a/.github/workflows/prepare-publish.yml +++ b/.github/workflows/prepare-publish.yml @@ -37,6 +37,8 @@ jobs: if: github.repository == 'vitest-dev/vitest' name: Prepare release PR runs-on: ubuntu-latest + # the app secrets live in an environment that only release branches can use + environment: release-bot permissions: contents: read # checkout target branch steps: diff --git a/.github/workflows/promote-docs.yml b/.github/workflows/promote-docs.yml index 1caaf29d5..4171cce05 100644 --- a/.github/workflows/promote-docs.yml +++ b/.github/workflows/promote-docs.yml @@ -8,11 +8,6 @@ on: required: false default: main type: string - secrets: - RELEASE_GITHUB_APP_ID: - required: true - RELEASE_GITHUB_APP_PRIVATE_KEY: - required: true workflow_dispatch: inputs: target: @@ -33,6 +28,9 @@ jobs: if: github.repository == 'vitest-dev/vitest' name: Promote stable documentation runs-on: ubuntu-slim + # the app secrets live in an environment that only release branches can use, + # a reusable workflow reads them from the environment, not from the caller + environment: release-bot steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 with: diff --git a/.github/workflows/publish.yml b/.github/workflows/publish.yml index 22b344f35..533c4d4df 100644 --- a/.github/workflows/publish.yml +++ b/.github/workflows/publish.yml @@ -140,6 +140,3 @@ jobs: uses: ./.github/workflows/promote-docs.yml with: target: ${{ github.sha }} - secrets: - RELEASE_GITHUB_APP_ID: ${{ secrets.RELEASE_GITHUB_APP_ID }} - RELEASE_GITHUB_APP_PRIVATE_KEY: ${{ secrets.RELEASE_GITHUB_APP_PRIVATE_KEY }} diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index 30c8a278f..5e3f472d4 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -209,6 +209,8 @@ A few settings outside this repository guard the release process above: GitHub r - required reviewer; publishing pauses until a maintainer approves the `Release` environment deployment. - self-review disabled; the maintainer who triggered the release cannot approve their own publish. - deployment restricted to `main` and the `v*` branches; a publish can only run from a real release branch, never from an arbitrary or feature branch. +- **release-bot environment** — holds the `vitest-release-bot` credentials for [`Prepare Publish`](./.github/workflows/prepare-publish.yml) and [`Promote Stable Docs`](./.github/workflows/promote-docs.yml); the `Release` environment holds its own copy for the tag push. + - deployment restricted to `main` and the `v*` branches; a workflow pushed to any other branch cannot use the app, which can bypass the tag ruleset and push to the `release` docs branch. - **npm publishing** — npm settings control how packages are authenticated and released. - trusted publishing (OIDC); each package's trusted publisher on npm pins the source repository (`vitest-dev/vitest`), workflow file (`publish.yml`), and environment (`Release`), so publishes use short-lived tokens from that workflow alone with no long-lived npm token to leak, and they carry provenance attestation automatically so users can trace a package back to the exact workflow run that produced it. - staged publishing; a publish run only stages the packages, and they go live only after a maintainer reviews and approves them on npm with 2FA, so a bad or accidental publish can be discarded before it becomes installable.