Use a dedicated PAT for Gitea package registry uploads
CI / lint (push) Successful in 9s
CI / test (push) Successful in 10s
CI / build (push) Successful in 23s
CI / publish (push) Successful in 11s
CI / notify (push) Successful in 5s

The automatic Actions token (GITEA_TOKEN) returns 401 against the
packages content API in this Gitea version, and GITEA_/GITHUB_-
prefixed names are reserved for secrets anyway. Switch to a
dedicated write:package-scoped token stored as PKG_REGISTRY_TOKEN.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_018n5ffHCn5QUjpDtuWTk3fh
This commit is contained in:
2026-09-27 23:36:36 +01:00
co-authored by Claude Sonnet 5
parent 7da2405d50
commit 0c669122ea
+6 -6
View File
@@ -90,26 +90,26 @@ jobs:
done done
- name: Upload plugin artifact to Gitea package registry - name: Upload plugin artifact to Gitea package registry
env: env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} PKG_REGISTRY_TOKEN: ${{ secrets.PKG_REGISTRY_TOKEN }}
BASE: ${{ github.server_url }}/api/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }} BASE: ${{ github.server_url }}/api/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }}
run: | run: |
if [[ "$GITHUB_REF" == refs/tags/v* ]]; then dirs="${GITHUB_REF_NAME#v}"; else dirs="main sha-${GITHUB_SHA::7}"; fi if [[ "$GITHUB_REF" == refs/tags/v* ]]; then dirs="${GITHUB_REF_NAME#v}"; else dirs="main sha-${GITHUB_SHA::7}"; fi
# Generic packages are immutable per version: delete first (ignored if absent) so # Generic packages are immutable per version: delete first (ignored if absent) so
# a re-run or a repeated push to a mutable version like "main" doesn't 409. # a re-run or a repeated push to a mutable version like "main" doesn't 409.
for dir in $dirs; do for dir in $dirs; do
curl -fsS -X DELETE -H "Authorization: token $GITEA_TOKEN" "$BASE/$dir" || true curl -fsS -X DELETE -H "Authorization: token $PKG_REGISTRY_TOKEN" "$BASE/$dir" || true
curl -fsS -X PUT -H "Authorization: token $GITEA_TOKEN" \ curl -fsS -X PUT -H "Authorization: token $PKG_REGISTRY_TOKEN" \
--upload-file "dist/${PLUGIN_ID}.ndp" "$BASE/$dir/${PLUGIN_ID}.ndp" --upload-file "dist/${PLUGIN_ID}.ndp" "$BASE/$dir/${PLUGIN_ID}.ndp"
curl -fsS -X PUT -H "Authorization: token $GITEA_TOKEN" \ curl -fsS -X PUT -H "Authorization: token $PKG_REGISTRY_TOKEN" \
--upload-file "manifest.json" "$BASE/$dir/manifest.json" --upload-file "manifest.json" "$BASE/$dir/manifest.json"
echo "uploaded $dir/${PLUGIN_ID}.ndp to Gitea packages" echo "uploaded $dir/${PLUGIN_ID}.ndp to Gitea packages"
done done
- name: Link Gitea package to this repo - name: Link Gitea package to this repo
env: env:
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN }} PKG_REGISTRY_TOKEN: ${{ secrets.PKG_REGISTRY_TOKEN }}
run: | run: |
repo_name="${GITHUB_REPOSITORY#*/}" repo_name="${GITHUB_REPOSITORY#*/}"
curl -fsS -X POST -H "Authorization: token $GITEA_TOKEN" \ curl -fsS -X POST -H "Authorization: token $PKG_REGISTRY_TOKEN" \
"${{ github.server_url }}/api/v1/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }}/-/link/$repo_name" \ "${{ github.server_url }}/api/v1/packages/${{ github.repository_owner }}/generic/${{ env.PLUGIN_ID }}/-/link/$repo_name" \
|| echo "link skipped (already linked, or not yet supported)" || echo "link skipped (already linked, or not yet supported)"