Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
19 changes: 16 additions & 3 deletions .github/workflows/ci-release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -91,13 +91,26 @@ jobs:
tag: ${{ steps.bump.outputs.tag }}
release_id: ${{ steps.create_release.outputs.id }}
steps:
# Admin PAT bypasses "require PR" on main (GITHUB_TOKEN cannot).
# Repo secret: RELEASE_GITHUB_TOKEN (classic repo scope, or fine-grained Contents R/W).
- name: Require release token
env:
RELEASE_GITHUB_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
run: |
if [[ -z "${RELEASE_GITHUB_TOKEN}" ]]; then
echo "Missing secret RELEASE_GITHUB_TOKEN." >&2
echo "Create a PAT for a repo admin (classic: repo scope, or fine-grained: Contents Read/Write)," >&2
echo "then add it as Settings → Secrets and variables → Actions → RELEASE_GITHUB_TOKEN." >&2
exit 1
fi

- name: Checkout base branch
uses: actions/checkout@v4
with:
ref: ${{ github.event_name == 'pull_request' && github.event.pull_request.base.ref || github.ref_name }}
fetch-depth: 0
fetch-tags: true
token: ${{ secrets.GITHUB_TOKEN }}
token: ${{ secrets.RELEASE_GITHUB_TOKEN }}

- name: Configure git
run: |
Expand Down Expand Up @@ -177,7 +190,7 @@ jobs:
- name: Create GitHub release
id: create_release
env:
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GH_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
TAG: ${{ steps.bump.outputs.tag }}
NOTES_FILE: ${{ steps.notes.outputs.path }}
run: |
Expand Down Expand Up @@ -259,7 +272,7 @@ jobs:
- name: Build and upload to release
uses: tauri-apps/tauri-action@v1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_TOKEN: ${{ secrets.RELEASE_GITHUB_TOKEN }}
with:
tagName: ${{ needs.version-and-release.outputs.tag }}
releaseId: ${{ needs.version-and-release.outputs.release_id }}
Expand Down
10 changes: 9 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -73,7 +73,15 @@ Example titles: `MINOR add dark mode default`, `MAJOR redesign library schema`,

Manual runs: pick `patch`, `minor`, or `major` in the workflow form.

Repo Settings → Actions → General → Workflow permissions must allow **Read and write** so the workflow can push the version commit, tag, and release assets.
### Release token (required)

`main` requires PRs, so the default `GITHUB_TOKEN` cannot push the version bump. Create a PAT for a **repo admin** and store it as the Actions secret `RELEASE_GITHUB_TOKEN`:

1. GitHub → Settings → Developer settings → Personal access tokens
2. Classic: enable the `repo` scope. Fine-grained: this repository, Contents **Read and write**
3. Repo → Settings → Secrets and variables → Actions → New repository secret → name `RELEASE_GITHUB_TOKEN`

Repo Settings → Actions → General → Workflow permissions should still allow **Read and write** for PR checks and other jobs.

### Windows installers and library path

Expand Down
Loading