security: limit Pages token to content updates
Publish GitHub Pages output / publish (push) Failing after 43s
Publish GitHub Pages output / publish (push) Failing after 43s
This commit is contained in:
@@ -52,4 +52,4 @@ npm run deploy:pages
|
||||
2. GitHub에서 `DD4SN/DD4SN.github.io` 저장소의 Contents 읽기/쓰기만 허용하는 fine-grained PAT를 발급합니다.
|
||||
3. 개인 Gitea 저장소의 Actions secret `PAGES_GITHUB_TOKEN`에 PAT를 등록합니다. Gitea는 secret 이름의 `GITHUB_` 접두사를 허용하지 않습니다.
|
||||
|
||||
토큰은 원본 저장소 파일, 로그, 생성 사이트에 기록하지 않습니다. GitHub Pages 저장소에 변경이 없으면 새 커밋을 만들지 않습니다.
|
||||
토큰은 원본 저장소 파일, 로그, 생성 사이트에 기록하지 않습니다. 자동 게시에서는 기존 `.github` 설정을 변경하지 않으므로 PAT에 Workflows 권한이 필요하지 않습니다. GitHub Pages 저장소에 정적 파일 변경이 없으면 새 커밋을 만들지 않습니다.
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
import { cp, mkdtemp, mkdir, readFile, rm, writeFile } from 'node:fs/promises';
|
||||
import { cp, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import process from 'node:process';
|
||||
@@ -7,7 +7,6 @@ import { fileURLToPath } from 'node:url';
|
||||
|
||||
const projectRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
|
||||
const siteSource = path.join(projectRoot, 'pages-dist');
|
||||
const workflowSource = path.join(projectRoot, 'pages', 'deploy.yml');
|
||||
const repository = process.env.GITHUB_PAGES_REPOSITORY ?? 'https://github.com/DD4SN/DD4SN.github.io.git';
|
||||
|
||||
if (!process.env.GITHUB_PAGES_TOKEN) {
|
||||
@@ -54,10 +53,6 @@ try {
|
||||
await cp(siteSource, checkout, { recursive: true });
|
||||
await writeFile(path.join(checkout, '.nojekyll'), '');
|
||||
|
||||
const workflowTarget = path.join(checkout, '.github', 'workflows');
|
||||
await mkdir(workflowTarget, { recursive: true });
|
||||
await cp(workflowSource, path.join(workflowTarget, 'deploy.yml'));
|
||||
|
||||
await requireGit(['config', 'user.name', 'HolodoriCalc deployment'], { cwd: checkout, env: gitEnvironment });
|
||||
await requireGit(['config', 'user.email', 'actions@users.noreply.github.com'], { cwd: checkout, env: gitEnvironment });
|
||||
await requireGit(['add', '--all', '--', '.'], { cwd: checkout, env: gitEnvironment });
|
||||
|
||||
Reference in New Issue
Block a user