Avoid using GITHUB_TOKEN for PR creation #26
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
his PR migrates the release workflow from using GITHUB_TOKEN with broad
pull-requests: write
permission to the more securedd-octo-sts
OIDC-based authentication system.Changes
.github/chainguard/self.release.create-pr.sts.yaml
with scoped permissions.github/workflows/release.yml
to use dd-octo-sts actionTesting
The workflow will continue to function exactly as before, creating Homebrew formula update PRs when new version tags are pushed, but now we can deactivate "create/approve PR" permission of the
GITHUB_TOKEN
.