Repository navigation
release: v2.0.4 - #33
cldmv-bot[bot] wants to merge 7 commits into
Conversation
…e and universal module support
| uses: CLDMV/.github/.github/workflows/release.yml@v1 | ||
| with: | ||
| package_name: "@cldmv/slothlet" # Required: Your NPM package name | ||
| debug: ${{ github.event_name == 'workflow_dispatch' && inputs.debug || false }} | ||
| # skip_matrix_tests: ${{ github.event_name == 'workflow_dispatch' && inputs.skip_matrix_tests || false }} | ||
|
|
||
| # Node.js Version Configuration (choose one approach) | ||
| # Option 1: Single Node.js version (simple) | ||
| # node_version: "lts/*" # Single Node.js version to test (default: lts/*) | ||
| # skip_matrix_tests: true # Use this with node_version (default: false) | ||
|
|
||
| # Option 2: Matrix testing (comprehensive) - DEFAULT BEHAVIOR | ||
| min_node_version: "16.4" # Minimum Node.js version for matrix testing (default: 20) | ||
| # max_node_major: "22" # Maximum Node.js major version (default: 22) | ||
|
|
||
| # Package & Build Configuration | ||
| # package_manager: "npm" # Package manager - npm or yarn (default: npm) | ||
| test_command: "npm test" # Command to run tests (default: npm test) | ||
| build_command: "npm run build:ci" # Command to build package (default: npm run build:ci) | ||
|
|
||
| # Release Configuration | ||
| # version_bump: "" # Type of version bump: patch, minor, major. Leave empty for auto-detection from commit message (default: "") | ||
| # version: "" # Specific version - auto-calculated if not provided (default: "") | ||
| # is_prerelease: false # Whether this is a prerelease (default: false) | ||
| # release_source_only: false # Create source-only release, no package assets (default: false) | ||
| # create_documentation: true # Create/update VERSION_TAGS.md (default: true) | ||
|
|
||
| # Test Control Options | ||
| # skip_performance_tests: false # Skip performance tests during CI (default: false) | ||
| # skip_matrix_tests: false # Skip matrix testing, use single version (default: false) | ||
|
|
||
| # Authentication & Bot Configuration | ||
| # The workflow supports automatic App token detection for enhanced permissions and proper attribution: | ||
| # - WITH App secrets: Operations attributed to CLDMV bot, enhanced permissions for workflow repositories | ||
| # - WITHOUT App secrets: Falls back to GitHub Actions bot with standard permissions | ||
| # To set up App authentication, add these secrets to your repository settings: | ||
| secrets: | ||
| NPM_TOKEN: ${{ secrets.NPM_TOKEN }} | ||
| # Optional: CLDMV Bot credentials for enhanced permissions and proper attribution | ||
| # If not provided, will use default GITHUB_TOKEN with GitHub Actions bot attribution | ||
| BOT_APP_ID: ${{ secrets.CLDMV_BOT_APP_ID }} | ||
| BOT_APP_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_APP_PRIVATE_KEY }} | ||
| TAGGER_NAME: ${{ secrets.CLDMV_BOT_NAME }} | ||
| TAGGER_EMAIL: ${{ secrets.CLDMV_BOT_EMAIL }} | ||
| GPG_PRIVATE_KEY: ${{ secrets.CLDMV_BOT_GPG_PRIVATE_KEY }} | ||
| GPG_PASSPHRASE: ${{ secrets.CLDMV_BOT_GPG_PASSPHRASE }} |
Check warning
Code scanning / CodeQL
Workflow does not contain permissions Medium
Show autofix suggestion
Hide autofix suggestion
Copilot Autofix
AI about 1 year ago
To remediate the issue, add a permissions block specifying the least necessary privileges. This is typically done either at the workflow root or under the job—in this case, either above jobs: or under create-release-pr:. Since the workflow only calls a reusable workflow for release PR creation, the likely minimal required scope is contents: read and pull-requests: write (since releasing may require creating PRs and reading repo contents). If the downstream workflow requires broader permissions, you should set only those privileges that are strictly necessary. The update should be at the root, affecting all jobs (since there is only one job), and must not interfere with secrets or other functionality.
Specifically:
- Insert a
permissions:block after thename:key (line 7). - Use least privilege recommended for release PRs:
permissions: contents: read pull-requests: write
No additional imports or dependency updates are needed.
| @@ -5,6 +5,9 @@ | ||
| # and uses smart commit analysis to determine if a release should be created. | ||
| # | ||
| name: 🚀 Create Release PR | ||
| permissions: | ||
| contents: read | ||
| pull-requests: write | ||
|
|
||
| on: | ||
| push: |
🚀 What's Changed
💥 Breaking Changes
✨ Features
No new features
🐛 Bug Fixes
No bug fixes
🔧 Other Changes
👥 Contributors