From 8fbb2330c742841e09f202de92f1c27f937b3c2c Mon Sep 17 00:00:00 2001 From: Joshua Gilman Date: Tue, 18 Aug 2026 20:17:07 -0700 Subject: [PATCH] fix(release): grant attestations read on the oci-image call job The v0.1.0 tag run failed at startup: 'The nested job oci-image is requesting attestations: read, but is only allowed attestations: none'. PR 2 added that permission to the callee in go-oci-build.yml, because the composite's installed acquisition path runs gh attestation verify, but did not raise the caller's ceiling in release.yml. A called workflow can never request more than the calling job grants. Consumer callers need the same grant, so the copyable example and the OCI how-to now document it. --- .github/workflows/release.yml | 4 ++++ docs/how-to/configure-oci-images.md | 13 +++++++++++++ examples/go-release/.github/workflows/release.yml | 3 +++ 3 files changed, 20 insertions(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 1427ea8..5fe2a39 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -75,6 +75,10 @@ jobs: needs: release-assets permissions: actions: read + # The callee installs setup-release-cli, whose installed acquisition path + # runs `gh attestation verify`. A called workflow can never exceed the + # caller's ceiling, so this must be granted here too. + attestations: read contents: read uses: ./.github/workflows/go-oci-build.yml with: diff --git a/docs/how-to/configure-oci-images.md b/docs/how-to/configure-oci-images.md index 9649d3c..aca7bc8 100644 --- a/docs/how-to/configure-oci-images.md +++ b/docs/how-to/configure-oci-images.md @@ -84,6 +84,19 @@ Use the complete caller in `examples/go-release/.github/workflows/release.yml` a 1. `oci-image` calls `go-oci-build.yml` with the canonical Linux artifact ID and digest from `release-assets`. 2. `oci-publish` calls `publish-oci-image.yml` with the authoritative OCI artifact ID, artifact digest, and image index digest from `oci-image`. +The builder job must grant these permissions: + +```yaml +permissions: + actions: read + attestations: read + contents: read +``` + +`attestations: read` is required because the builder installs `release-cli` and +verifies its attestation. A called workflow can never request more than the +calling job grants, so omitting it fails the run before any job starts. + The publisher job must grant only these permissions: ```yaml diff --git a/examples/go-release/.github/workflows/release.yml b/examples/go-release/.github/workflows/release.yml index 9125f4c..be25623 100644 --- a/examples/go-release/.github/workflows/release.yml +++ b/examples/go-release/.github/workflows/release.yml @@ -25,6 +25,9 @@ jobs: needs: release-assets permissions: actions: read + # Required because the called workflow verifies the release-cli + # attestation while installing it; a callee cannot exceed this ceiling. + attestations: read contents: read uses: meigma/release/.github/workflows/go-oci-build.yml@fb8c8098ff27968fb3070e928c00e925f38c698e with: