From 139d451d4cda89aca86d25e6cd0e8233eedc9348 Mon Sep 17 00:00:00 2001 From: Jarry Shaw Date: Tue, 15 Sep 2026 18:51:33 -0400 Subject: [PATCH] ci: use deploy key for protected maintenance pushes --- .github/workflows/create-release.yml | 20 ++++++++++++-------- .github/workflows/cron-conda.yml | 27 +++++++++++++++++---------- .github/workflows/cron-vendor.yml | 14 +++++++++----- 3 files changed, 38 insertions(+), 23 deletions(-) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index a92cfe5b72..4dcd421942 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -123,6 +123,11 @@ jobs: needs: [ version_check ] if: ${{ startsWith(github.ref_name, 'v') || needs.version_check.outputs.PCAPKIT_TAG_EXISTS == 'false' }} steps: + - name: Load maintenance deploy key + uses: webfactory/ssh-agent@v0.9.1 + with: + ssh-private-key: ${{ secrets.PYPCAPKIT_ACTIONS_DEPLOY_KEY }} + - name: Checkout code uses: actions/checkout@v7 with: @@ -147,9 +152,10 @@ jobs: git commit -m"Reset conda build number" || true - name: Push Changes - uses: ad-m/github-push-action@master - with: - github_token: ${{ secrets.PYPCAPKIT }} + run: | + git remote set-url origin git@github.com:JarryShaw/PyPCAPKit.git + git pull --rebase origin main + git push origin HEAD:main - name: Create Tag run: | @@ -162,11 +168,9 @@ jobs: git tag "conda-${{ needs.version_check.outputs.PCAPKIT_VERSION }}+0" -m"Conda Build" - name: Push Tag - uses: ad-m/github-push-action@master - with: - github_token: ${{ secrets.PYPCAPKIT }} - atomic: false - tags: true + run: | + git remote set-url origin git@github.com:JarryShaw/PyPCAPKit.git + git push origin "conda-${{ needs.version_check.outputs.PCAPKIT_VERSION }}+0" pypi: name: PyPI distribution for Python ${{ matrix.python-version }} diff --git a/.github/workflows/cron-conda.yml b/.github/workflows/cron-conda.yml index 8a9a5dc7dc..35521fd827 100644 --- a/.github/workflows/cron-conda.yml +++ b/.github/workflows/cron-conda.yml @@ -40,6 +40,11 @@ jobs: permissions: contents: write steps: + - name: Load maintenance deploy key + uses: webfactory/ssh-agent@v0.9.1 + with: + ssh-private-key: ${{ secrets.PYPCAPKIT_ACTIONS_DEPLOY_KEY }} + - uses: actions/checkout@v7 with: fetch-depth: 0 @@ -83,12 +88,11 @@ jobs: ${{ steps.verify-changed-files.outputs.changed_files }}" - name: Push Changes - uses: ad-m/github-push-action@master if: steps.verify-changed-files.outputs.files_changed == 'true' - with: - github_token: ${{ secrets.GITHUB_TOKEN }} - branch: ${{ github.ref }} - pull: rebase + run: | + git remote set-url origin git@github.com:JarryShaw/PyPCAPKit.git + git pull --rebase origin "${GITHUB_REF#refs/heads/}" + git push origin "HEAD:${GITHUB_REF}" - name: Get Version if: steps.verify-changed-files.outputs.files_changed == 'true' @@ -116,6 +120,11 @@ jobs: permissions: contents: write steps: + - name: Load maintenance deploy key + uses: webfactory/ssh-agent@v0.9.1 + with: + ssh-private-key: ${{ secrets.PYPCAPKIT_ACTIONS_DEPLOY_KEY }} + - name: Checkout code uses: actions/checkout@v7 with: @@ -133,11 +142,9 @@ jobs: git tag "conda-${{ needs.conda-update.outputs.PCAPKIT_VERSION }}+${{ needs.conda-update.outputs.PCAPKIT_BUILD }}" -m"Conda Build" - name: Push Tag - uses: ad-m/github-push-action@master - with: - github_token: ${{ secrets.PYPCAPKIT }} - atomic: false - tags: true + run: | + git remote set-url origin git@github.com:JarryShaw/PyPCAPKit.git + git push origin "conda-${{ needs.conda-update.outputs.PCAPKIT_VERSION }}+${{ needs.conda-update.outputs.PCAPKIT_BUILD }}" conda-dist: name: Conda deployment (update) on ${{ matrix.os }} with Python ${{ matrix.python-version }} diff --git a/.github/workflows/cron-vendor.yml b/.github/workflows/cron-vendor.yml index 509c3fb013..6106070e76 100644 --- a/.github/workflows/cron-vendor.yml +++ b/.github/workflows/cron-vendor.yml @@ -37,6 +37,11 @@ jobs: permissions: contents: write steps: + - name: Load maintenance deploy key + uses: webfactory/ssh-agent@v0.9.1 + with: + ssh-private-key: ${{ secrets.PYPCAPKIT_ACTIONS_DEPLOY_KEY }} + - uses: actions/checkout@v7 - uses: actions/setup-python@v7 @@ -86,12 +91,11 @@ jobs: have been changed: ${{ steps.verify-changed-files.outputs.changed_files }}" - name: Push changes - uses: ad-m/github-push-action@master if: steps.verify-changed-files.outputs.files_changed == 'true' - with: - github_token: ${{ secrets.GITHUB_TOKEN }} - branch: ${{ github.ref }} - pull: rebase + run: | + git remote set-url origin git@github.com:JarryShaw/PyPCAPKit.git + git pull --rebase origin "${GITHUB_REF#refs/heads/}" + git push origin "HEAD:${GITHUB_REF}" # - name: Create Tag # if: steps.verify-changed-files.outputs.files_changed == 'true'