diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index e3fea92..b1b942f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -88,10 +88,12 @@ jobs: published: ${{ steps.before.outputs.version != steps.after.outputs.version }} version: ${{ steps.after.outputs.version }} steps: + # main's own ruleset requires the "Required Checks" status and blocks direct pushes, and the default GITHUB_TOKEN has no way to bypass a repository ruleset (GitHub doesn't support naming the github-actions[bot] identity as a bypass actor at all) -- so semantic-release's own release-commit/tag push needs a bypass identity. A deploy key with write access, added as a DeployKey bypass actor on the ruleset, is the lightest-weight one: repo-scoped, no GitHub App installation to manage, no personal/org-admin credential involved. - uses: actions/checkout@v7 with: # semantic-release analyses the full commit history since the last release. fetch-depth: 0 + ssh-key: ${{ secrets.RELEASE_DEPLOY_KEY }} - uses: pnpm/action-setup@v6 - uses: actions/setup-node@v7 with: