diff --git a/.github/workflows/ci-release.yml b/.github/workflows/ci-release.yml index a594812..ef3878c 100644 --- a/.github/workflows/ci-release.yml +++ b/.github/workflows/ci-release.yml @@ -91,13 +91,26 @@ jobs: tag: ${{ steps.bump.outputs.tag }} release_id: ${{ steps.create_release.outputs.id }} steps: + # Admin PAT bypasses "require PR" on main (GITHUB_TOKEN cannot). + # Repo secret: RELEASE_GITHUB_TOKEN (classic repo scope, or fine-grained Contents R/W). + - name: Require release token + env: + RELEASE_GITHUB_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }} + run: | + if [[ -z "${RELEASE_GITHUB_TOKEN}" ]]; then + echo "Missing secret RELEASE_GITHUB_TOKEN." >&2 + echo "Create a PAT for a repo admin (classic: repo scope, or fine-grained: Contents Read/Write)," >&2 + echo "then add it as Settings → Secrets and variables → Actions → RELEASE_GITHUB_TOKEN." >&2 + exit 1 + fi + - name: Checkout base branch uses: actions/checkout@v4 with: ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.ref || github.ref_name }} fetch-depth: 0 fetch-tags: true - token: ${{ secrets.GITHUB_TOKEN }} + token: ${{ secrets.RELEASE_GITHUB_TOKEN }} - name: Configure git run: | @@ -177,7 +190,7 @@ jobs: - name: Create GitHub release id: create_release env: - GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GH_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }} TAG: ${{ steps.bump.outputs.tag }} NOTES_FILE: ${{ steps.notes.outputs.path }} run: | @@ -259,7 +272,7 @@ jobs: - name: Build and upload to release uses: tauri-apps/tauri-action@v1 env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + GITHUB_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }} with: tagName: ${{ needs.version-and-release.outputs.tag }} releaseId: ${{ needs.version-and-release.outputs.release_id }} diff --git a/README.md b/README.md index 22ee6a6..4c3e425 100644 --- a/README.md +++ b/README.md @@ -73,7 +73,15 @@ Example titles: `MINOR add dark mode default`, `MAJOR redesign library schema`, Manual runs: pick `patch`, `minor`, or `major` in the workflow form. -Repo Settings → Actions → General → Workflow permissions must allow **Read and write** so the workflow can push the version commit, tag, and release assets. +### Release token (required) + +`main` requires PRs, so the default `GITHUB_TOKEN` cannot push the version bump. Create a PAT for a **repo admin** and store it as the Actions secret `RELEASE_GITHUB_TOKEN`: + +1. GitHub → Settings → Developer settings → Personal access tokens +2. Classic: enable the `repo` scope. Fine-grained: this repository, Contents **Read and write** +3. Repo → Settings → Secrets and variables → Actions → New repository secret → name `RELEASE_GITHUB_TOKEN` + +Repo Settings → Actions → General → Workflow permissions should still allow **Read and write** for PR checks and other jobs. ### Windows installers and library path