Skip to content

Commit 75c6fe9

Browse files
committed
fix(ci): 发版工作流改用 RELEASE_TOKEN 以绕过 main 分支保护
前两次 Version & Release 均失败于 GH013:main 的 ruleset 强制 "Changes must be made through a pull request",把 semantic-release 自身的发版推送(chore(release) 提交 + CHANGELOG + tag → HEAD:main) 一并拦截。 修复:checkout 与 semantic-release 环境改用 secrets.RELEASE_TOKEN (细粒度 PAT,Contents:RW,持有者为仓库 admin),配合 ruleset Bypass list(Repository admin)实现发版链路的受控绕过; 未配置该 secret 时回退内置 token,行为与现状一致(不劣化)。 需要仓库侧配套(手工步骤): 1) 创建细粒度 PAT(仅 Entropydecrease 仓库,Contents: Read and write) 2) 仓库 Settings → Secrets → Actions 新建 RELEASE_TOKEN 3) main-protection ruleset → Bypass list 添加 Repository admin
1 parent b1583c4 commit 75c6fe9

1 file changed

Lines changed: 6 additions & 1 deletion

File tree

‎.github/workflows/version-release.yml‎

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,6 +31,10 @@ jobs:
3131
with:
3232
fetch-depth: 0
3333
persist-credentials: true
34+
# RELEASE_TOKEN:细粒度 PAT(Contents:RW),持有者为仓库 admin,
35+
# 配合 ruleset Bypass list(Repository admin)绕过 main 的 PR 强制规则;
36+
# 未配置该 secret 时回退内置 token(checkout 可用,push 仍会被规则拦截)
37+
token: ${{ secrets.RELEASE_TOKEN || github.token }}
3438

3539
- name: Setup Node
3640
uses: actions/setup-node@v4
@@ -42,5 +46,6 @@ jobs:
4246

4347
- name: Semantic Release
4448
env:
45-
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
49+
# 同上:semantic-release 的 git push 与 GitHub Release 创建均使用 PAT
50+
GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN || secrets.GITHUB_TOKEN }}
4651
run: npx semantic-release

0 commit comments

Comments
 (0)