diff --git a/.forgejo/workflows/release.yaml b/.forgejo/workflows/release.yaml index 31a7b6e..bc9ebd6 100644 --- a/.forgejo/workflows/release.yaml +++ b/.forgejo/workflows/release.yaml @@ -1,16 +1,30 @@ name: Release on: - push: - tags: ["*"] + release: + types: [published] -permissions: - contents: write +enable-openid-connect: true jobs: publish: runs-on: nix steps: + - name: fetch jwt + id: jwt + env: + AUD: u:168061:141d46eb-9b70-4c27-9d49-db5b30b6da28 + run: | + jwt=$( \ + curl --fail \ + -H "Authorization: bearer $ACTIONS_ID_TOKEN_REQUEST_TOKEN" \ + "$ACTIONS_ID_TOKEN_REQUEST_URL&audience=$AUD" \ + | jq -r ".value" \ + ) + # ::add-mask:: tells Forgejo Runner that the JWT + # is a secret which should be masked in the logs. + echo "::add-mask::$jwt" + echo "jwt=$jwt" >> $FORGEJO_OUTPUT - uses: actions/checkout@v4 - uses: https://codeberg.org/icewind/attic-action@v1 with: @@ -24,8 +38,10 @@ jobs: cp result/bin/haze assets/$asset done - name: Create release - uses: https://code.forgejo.org/actions/forgejo-release@v2.7.3 + # https://code.forgejo.org/actions/forgejo-release/issues/121 + uses: https://code.forgejo.org/astrelion/forgejo-release@b523d26318949212b87ef4a5a19a5ee9218d0c20 with: direction: upload release-dir: assets - token: "${{ secrets.FORGEJO_TOKEN }}" + only-assets: true + token: "${{ steps.jwt.outputs.jwt }}"