mirror of
https://github.com/d4rken-org/capod.git
synced 2026-09-14 18:26:11 -04:00
release: published events triggered by secrets.GITHUB_TOKEN do not start new workflow runs (only workflow_dispatch and repository_dispatch are exceptions). The Pages workflow's release: published trigger would never have fired in production since release-tag.yml's softprops/action-gh-release uses GITHUB_TOKEN to publish. Fix: drop the release: published trigger and have release-tag.yml's release-github job explicitly run gh workflow run pages.yml --ref main after the release is created. release-github gains actions: write to authorize the dispatch. Also adopts refinements from sibling org PRs (permission-pilot#356, bluemusic#220): - Top-level permissions reduced to contents: read; pages: write and id-token: write moved to the deploy job only (least privilege) - JEKYLL_GITHUB_TOKEN on the build step so jekyll-github-metadata authenticates when fetching site.github.releases - Sanity-check step (test -f _site/index.html && _site/CNAME) fails fast if Jekyll produced nothing - Explicit upload-pages-artifact path: ./_site matches the build's destination - Verify fastlane Bundler wiring step (bundle exec fastlane --version) lets workflow_dispatch dry_run=true exercise the relocated Gemfile before the next real release