Skip to content

Commit dc1ada6

Browse files
authored
add octo-sts (#149)
1 parent 34c6657 commit dc1ada6

2 files changed

Lines changed: 16 additions & 3 deletions

File tree

.github/chainguard/write.sts.yaml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
# yaml-language-server: $schema=https://raw.githubusercontent.com/octo-sts/app/refs/heads/main/pkg/octosts/octosts.TrustPolicy.json
2+
issuer: https://token.actions.githubusercontent.com
3+
subject: repo:prefix-dev/pixi-docker:ref:refs/heads/main
4+
5+
permissions:
6+
contents: write
7+
pull_requests: write

.github/workflows/bump.yml

Lines changed: 9 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,8 @@ jobs:
1010
name: Reference latest Pixi version in README
1111
runs-on: ubuntu-latest
1212
permissions:
13-
contents: write
14-
pull-requests: write
13+
contents: read
14+
id-token: write
1515
steps:
1616
- uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2
1717

@@ -26,11 +26,17 @@ jobs:
2626
env:
2727
GH_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2828

29+
- uses: octo-sts/action@f603d3be9d8dd9871a265776e625a27b00effe05 # v1.1.1
30+
id: octo-sts
31+
with:
32+
scope: ${{ github.repository }}
33+
identity: write
34+
2935
- name: Create pull request
3036
uses: peter-evans/create-pull-request@c0f553fe549906ede9cf27b5156039d195d2ece0 # v8.1.0
3137
if: github.ref_name == 'main'
3238
with:
33-
token: ${{ secrets.GITHUB_TOKEN }}
39+
token: ${{ steps.octo-sts.outputs.token }}
3440
commit-message: Bump pixi version to ${{ steps.bump.outputs.latest-version }}
3541
title: Bump pixi version to ${{ steps.bump.outputs.latest-version }}
3642
labels: enhancement

0 commit comments

Comments
 (0)