diff --git a/.forgejo/workflows/release.yml b/.forgejo/workflows/release.yml index 3dd00e7a..008ee3f3 100644 --- a/.forgejo/workflows/release.yml +++ b/.forgejo/workflows/release.yml @@ -6,14 +6,10 @@ # publishes a Forgejo release via rasterstate/forgejo-release-action and # uploads the APK as an asset. # -# Authentication uses ${{ secrets.GITHUB_TOKEN }} (auto-provided by the -# Forgejo runner, scoped to contents: write for the current repo). A -# dedicated PAT (${{ secrets.RELEASE_TOKEN }}) was the preferred option -# for least-privilege, but creating repo-level secrets is currently -# broken on this Forgejo instance (InsertEncryptedSecret fails with a -# UTF-8 byte-sequence error, probably a text-vs-bytea column type on -# the secret table). Bumping to Forgejo v16 should fix it; until then, -# the runner-provided token keeps the workflow operational. +# Authentication uses ${{ secrets.RELEASE_TOKEN }}, a Forgejo PAT scoped +# to `write:repository` configured in the repository's Actions secrets. +# The runner-provided ${{ secrets.GITHUB_TOKEN }} would also work, but +# a dedicated PAT is preferred for least-privilege and revocability. # # This workflow complements .github/workflows/docker-publish-android.yml # which targets the GitHub mirror; the validate-release logic mirrors @@ -228,4 +224,4 @@ jobs: files: | PostIt.Android.apk env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} \ No newline at end of file + GITHUB_TOKEN: ${{ secrets.RELEASE_TOKEN }} \ No newline at end of file