Skip to content

Commit 6d04c06

Browse files
committed
ci: improvement permissions
1 parent 17441f8 commit 6d04c06

File tree

1 file changed

+10
-6
lines changed

1 file changed

+10
-6
lines changed

.github/workflows/release-plz.yml

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -6,10 +6,6 @@ on:
66
branches:
77
- main
88

9-
permissions:
10-
pull-requests: write
11-
contents: write
12-
139
jobs:
1410
release-plz:
1511
name: Release-plz
@@ -18,6 +14,7 @@ jobs:
1814
- uses: actions/checkout@v4
1915
with:
2016
fetch-depth: 0
17+
token: ${{ secrets.OXC_BOT_PAT }}
2118

2219
- uses: Boshen/setup-rust@main
2320
with:
@@ -27,19 +24,26 @@ jobs:
2724
- name: Run release-plz
2825
id: release-plz
2926
uses: MarcoIeni/[email protected]
27+
permissions:
28+
pull-requests: write
29+
contents: write
3030
env:
31-
GITHUB_TOKEN: ${{ secrets.RELEASE_PLZ_TOKEN }}
31+
GITHUB_TOKEN: ${{ secrets.OXC_BOT_PAT }}
3232
CARGO_REGISTRY_TOKEN: ${{ secrets.CARGO_REGISTRY_TOKEN }}
3333

3434
- name: Bump package.json
3535
if: ${{ steps.release-plz.outputs.prs_created }}
36+
permissions:
37+
pull-requests: write
3638
env:
37-
GH_TOKEN: ${{ github.token }}
39+
GH_TOKEN: ${{ secrets.OXC_BOT_PAT }}
3840
RELEASES: ${{ steps.release-plz.outputs.releases }}
3941
PR: ${{ steps.release-plz.outputs.pr }}
4042
run: |
4143
set -e
4244
45+
echo $RELEASES
46+
4347
pr_number=${{ fromJSON(steps.release-plz.outputs.pr).number }}
4448
if [[ -n "$pr_number" ]]; then
4549
version=$(echo "$RELEASES" | jq -r '.[0].version')

0 commit comments

Comments
 (0)