From 72add0f0ac56785386afc0bbcbbc370c9c13e808 Mon Sep 17 00:00:00 2001 From: Amir Husayn Panahifar Date: Sat, 12 Sep 2026 16:06:30 +0330 Subject: [PATCH] ci: drop env token; rely on permissions: releases: write for release upload --- .gitea/workflows/ci.yml | 9 ++++----- 1 file changed, 4 insertions(+), 5 deletions(-) diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index f2847b0..f5fb0d6 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -159,22 +159,21 @@ jobs: path: dist-deb/*.deb - name: Create Gitea release and upload assets - env: - GITEA_TOKEN: ${{ github.token }} run: | set -euo pipefail api="${{ github.server_url }}/api/v1" repo="${{ github.repository }}" tag="${{ github.ref_name }}" payload="{\"tag_name\":\"$tag\",\"name\":\"$tag\"}" + token="${{ secrets.GITEA_TOKEN }}" out=$(curl -sS -X POST "$api/repos/$repo/releases" \ - -H "Authorization: token $GITEA_TOKEN" \ + -H "Authorization: token $token" \ -H "Content-Type: application/json" \ -d "$payload" || true) if ! printf '%s' "$out" | grep -q '"id"'; then out=$(curl -sS "$api/repos/$repo/releases/tags/$tag" \ - -H "Authorization: token $GITEA_TOKEN") + -H "Authorization: token $token") fi rid=$(printf '%s' "$out" | grep -o '"id":[0-9]*' | head -1 | cut -d: -f2) [ -n "$rid" ] || { echo "release id not found" >&2; exit 1; } @@ -182,7 +181,7 @@ jobs: for f in dist/*.whl dist-deb/*.deb; do [ -e "$f" ] || continue curl -fsS -X POST "$api/repos/$repo/releases/$rid/assets?name=$(basename "$f")" \ - -H "Authorization: token $GITEA_TOKEN" \ + -H "Authorization: token $token" \ --data-binary @"$f" echo "Uploaded $(basename "$f")" done