Skip to content

Commit 52e9c1b

Browse files
authored
github-action: add attestations scope (#2032)
1 parent ffc0861 commit 52e9c1b

File tree

3 files changed

+7
-7
lines changed

3 files changed

+7
-7
lines changed

.github/actions/packages/action.yml

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,3 @@ runs:
2525
path: |
2626
dist/*.whl
2727
dist/*tar.gz
28-
- name: generate build provenance
29-
uses: github-early-access/generate-build-provenance@main
30-
with:
31-
subject-path: "${{ github.workspace }}/dist/*"

.github/workflows/packages.yml

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,9 +18,6 @@ permissions:
1818

1919
jobs:
2020
build:
21-
permissions:
22-
id-token: write
23-
contents: write
2421
runs-on: ubuntu-latest
2522
steps:
2623
- uses: actions/checkout@v4

.github/workflows/release.yml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,12 +19,17 @@ jobs:
1919

2020
packages:
2121
permissions:
22+
attestations: write
2223
id-token: write
2324
contents: write
2425
runs-on: ubuntu-latest
2526
steps:
2627
- uses: actions/checkout@v4
2728
- uses: ./.github/actions/packages
29+
- name: generate build provenance
30+
uses: github-early-access/generate-build-provenance@main
31+
with:
32+
subject-path: "${{ github.workspace }}/dist/*"
2833

2934
publish-pypi:
3035
needs:
@@ -53,6 +58,7 @@ jobs:
5358

5459
build-distribution:
5560
permissions:
61+
attestations: write
5662
id-token: write
5763
contents: write
5864
runs-on: ubuntu-latest
@@ -103,6 +109,7 @@ jobs:
103109
- build-distribution
104110
runs-on: ubuntu-latest
105111
permissions:
112+
attestations: write
106113
id-token: write
107114
contents: write
108115
env:

0 commit comments

Comments
 (0)