Repository navigation
Release from a protected environment and push the README with a GitHub App - #24
Merged
Merged
Conversation
…b App The publish job now reads the Maven Central and signing secrets from the protected `release` environment, which admits only v* tags and waits for a maintainer's approval, so no other workflow, branch or job can read them. The README version update is pushed with a short-lived token of the release GitHub App instead of GITHUB_TOKEN: the app is on the bypass list of the main branch ruleset, the token can only write repository contents, and its push triggers CI on the README commit. The job reads the app's private key from the same environment, commits as the app's bot user and no longer needs contents: write on GITHUB_TOKEN. RELEASING.md describes the environment, its secrets and the release app. actionlint's bundled metadata of create-github-app-token predates its client-id input, so the two resulting errors are ignored for the release workflow.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
publishusesenvironment: release. The Maven Central and signing secrets now live in that environment, which admits onlyv*tags and requires a maintainer's approval.update-readmeuses the same environment. It gets a short-lived token fromactions/create-github-app-token@v3(theRELEASE_APP_CLIENT_IDorganization secret and theRELEASE_APP_PRIVATE_KEYenvironment secret), and that token can only write repository contents. The job checks out and pushes the README update with it, commits as<app-slug>[bot], and no longer needscontents: writeonGITHUB_TOKEN. The release app can be on the main branch ruleset's bypass list, and its push triggers CI on the README commit.RELEASING.mddocuments thereleaseenvironment, its secrets, the release app, andGRADLE_ENCRYPTION_KEY..github/actionlint.yamlignores two actionlint errors aboutcreate-github-app-tokeninrelease.yml. actionlint 1.7.12's bundled metadata for that action is older than itsclient-idinput.Setup this depends on
jonoffcpu/jonoffcpuand has the Contents read and write permission.mainruleset when the ruleset is active.releaseenvironment holdsMAVEN_CENTRAL_USERNAME,MAVEN_CENTRAL_PASSWORD,SIGNING_IN_MEMORY_KEY,SIGNING_IN_MEMORY_KEY_ID,SIGNING_IN_MEMORY_KEY_PASSWORDandRELEASE_APP_PRIVATE_KEY, and no repository or organization copies of these remain.Each release waits for two approvals, one for
publishand one forupdate-readme.Verification
actionlint1.7.12 (local and the pinned Docker image) andzizmor1.30.1 with online audits pass.v*tag.