Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 1 addition & 3 deletions .github/workflows/ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -88,15 +88,13 @@ jobs:
published: ${{ steps.before.outputs.version != steps.after.outputs.version }}
version: ${{ steps.after.outputs.version }}
steps:
# main's own ruleset requires the "Required Checks" status and blocks direct pushes, and the default GITHUB_TOKEN has no way to bypass a repository ruleset (GitHub doesn't support naming the github-actions[bot] identity as a bypass actor at all) -- so semantic-release's own release-commit/tag push needs a bypass identity. A deploy key with write access, added as a DeployKey bypass actor on the ruleset, is the lightest-weight one: repo-scoped, no GitHub App installation to manage, no personal/org-admin credential involved.
# main's own ruleset requires the "Required Checks" status and blocks direct pushes, and the default GITHUB_TOKEN has no way to bypass a repository ruleset (GitHub doesn't support naming the github-actions[bot] identity as a bypass actor at all) -- so semantic-release's own release-commit/tag push needs a bypass identity. A deploy key with write access, added as a DeployKey bypass actor on the ruleset, is the lightest-weight one: repo-scoped, no GitHub App installation to manage, no personal/org-admin credential involved. ssh-key only wires the key into core.sshCommand for later git commands to use -- release.config.ts's own repositoryUrl is what actually makes semantic-release's push go out over SSH instead of an https:// URL with the default GITHUB_TOKEN embedded.
- uses: actions/checkout@v7
with:
# semantic-release analyses the full commit history since the last release.
fetch-depth: 0
ssh-key: ${{ secrets.RELEASE_DEPLOY_KEY }}
# ssh-key only wires the deploy key into core.sshCommand for actions/checkout's own git commands -- it does not rewrite the "origin" remote or any later command's push URL. @semantic-release/git constructs its push against a plain https://github.com/... URL, which persist-credentials would otherwise satisfy with the default GITHUB_TOKEN instead of the deploy key, so that credential is turned off and every https://github.com/ URL is rewritten to the SSH form the deploy key actually authenticates.
persist-credentials: false
- run: git config --global url."git@github.com:".insteadOf "https://github.com/"
- uses: pnpm/action-setup@v6
- uses: actions/setup-node@v7
with:
Expand Down
2 changes: 2 additions & 0 deletions release.config.ts
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,8 @@ export const commitTypes: readonly CommitType[] = [
*/
const config: Options = {
branches: ['main'],
// Deliberately the SSH form, not package.json's own git+https:// repository field (that field stays https:// -- it's public consumer-facing metadata, unrelated to how this release pushes). semantic-release only embeds an x-access-token:$GITHUB_TOKEN@ credential into an https:// repositoryUrl; the default GITHUB_TOKEN it would embed has no way to bypass main's branch ruleset. An SSH URL skips that embedding entirely and pushes using whatever key actions/checkout's ssh-key input already wired into core.sshCommand -- the deploy key added as a DeployKey bypass actor on the ruleset.
repositoryUrl: 'git@github.com:ExaDev/eslint-config.git',
plugins: [
[
'@semantic-release/commit-analyzer',
Expand Down