Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -75,6 +75,10 @@ jobs:
needs: release-assets
permissions:
actions: read
# The callee installs setup-release-cli, whose installed acquisition path
# runs `gh attestation verify`. A called workflow can never exceed the
# caller's ceiling, so this must be granted here too.
attestations: read
contents: read
uses: ./.github/workflows/go-oci-build.yml
with:
Expand Down
13 changes: 13 additions & 0 deletions docs/how-to/configure-oci-images.md
Original file line number Diff line number Diff line change
Expand Up @@ -84,6 +84,19 @@ Use the complete caller in `examples/go-release/.github/workflows/release.yml` a
1. `oci-image` calls `go-oci-build.yml` with the canonical Linux artifact ID and digest from `release-assets`.
2. `oci-publish` calls `publish-oci-image.yml` with the authoritative OCI artifact ID, artifact digest, and image index digest from `oci-image`.

The builder job must grant these permissions:

```yaml
permissions:
actions: read
attestations: read
contents: read
```

`attestations: read` is required because the builder installs `release-cli` and
verifies its attestation. A called workflow can never request more than the
calling job grants, so omitting it fails the run before any job starts.

The publisher job must grant only these permissions:

```yaml
Expand Down
3 changes: 3 additions & 0 deletions examples/go-release/.github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,9 @@ jobs:
needs: release-assets
permissions:
actions: read
# Required because the called workflow verifies the release-cli
# attestation while installing it; a callee cannot exceed this ceiling.
attestations: read
contents: read
uses: meigma/release/.github/workflows/go-oci-build.yml@fb8c8098ff27968fb3070e928c00e925f38c698e
with:
Expand Down