From dac6ccda308ff43212d9abd291a44798aed24222 Mon Sep 17 00:00:00 2001 From: dal4segno Date: Mon, 31 Aug 2026 13:04:35 +0900 Subject: [PATCH] security: limit Pages token to content updates --- docs/github-pages-deployment.md | 2 +- scripts/publish-pages.mjs | 7 +------ 2 files changed, 2 insertions(+), 7 deletions(-) diff --git a/docs/github-pages-deployment.md b/docs/github-pages-deployment.md index 5f1c800..6ddf25f 100644 --- a/docs/github-pages-deployment.md +++ b/docs/github-pages-deployment.md @@ -52,4 +52,4 @@ npm run deploy:pages 2. GitHub에서 `DD4SN/DD4SN.github.io` 저장소의 Contents 읽기/쓰기만 허용하는 fine-grained PAT를 발급합니다. 3. 개인 Gitea 저장소의 Actions secret `PAGES_GITHUB_TOKEN`에 PAT를 등록합니다. Gitea는 secret 이름의 `GITHUB_` 접두사를 허용하지 않습니다. -토큰은 원본 저장소 파일, 로그, 생성 사이트에 기록하지 않습니다. GitHub Pages 저장소에 변경이 없으면 새 커밋을 만들지 않습니다. +토큰은 원본 저장소 파일, 로그, 생성 사이트에 기록하지 않습니다. 자동 게시에서는 기존 `.github` 설정을 변경하지 않으므로 PAT에 Workflows 권한이 필요하지 않습니다. GitHub Pages 저장소에 정적 파일 변경이 없으면 새 커밋을 만들지 않습니다. diff --git a/scripts/publish-pages.mjs b/scripts/publish-pages.mjs index 44224b7..f46863b 100644 --- a/scripts/publish-pages.mjs +++ b/scripts/publish-pages.mjs @@ -1,4 +1,4 @@ -import { cp, mkdtemp, mkdir, readFile, rm, writeFile } from 'node:fs/promises'; +import { cp, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises'; import os from 'node:os'; import path from 'node:path'; import process from 'node:process'; @@ -7,7 +7,6 @@ import { fileURLToPath } from 'node:url'; const projectRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..'); const siteSource = path.join(projectRoot, 'pages-dist'); -const workflowSource = path.join(projectRoot, 'pages', 'deploy.yml'); const repository = process.env.GITHUB_PAGES_REPOSITORY ?? 'https://github.com/DD4SN/DD4SN.github.io.git'; if (!process.env.GITHUB_PAGES_TOKEN) { @@ -54,10 +53,6 @@ try { await cp(siteSource, checkout, { recursive: true }); await writeFile(path.join(checkout, '.nojekyll'), ''); - const workflowTarget = path.join(checkout, '.github', 'workflows'); - await mkdir(workflowTarget, { recursive: true }); - await cp(workflowSource, path.join(workflowTarget, 'deploy.yml')); - await requireGit(['config', 'user.name', 'HolodoriCalc deployment'], { cwd: checkout, env: gitEnvironment }); await requireGit(['config', 'user.email', 'actions@users.noreply.github.com'], { cwd: checkout, env: gitEnvironment }); await requireGit(['add', '--all', '--', '.'], { cwd: checkout, env: gitEnvironment });