security: limit Pages token to content updates
Publish GitHub Pages output / publish (push) Failing after 43s
Publish GitHub Pages output / publish (push) Failing after 43s
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
import { cp, mkdtemp, mkdir, readFile, rm, writeFile } from 'node:fs/promises';
|
||||
import { cp, mkdtemp, readFile, rm, writeFile } from 'node:fs/promises';
|
||||
import os from 'node:os';
|
||||
import path from 'node:path';
|
||||
import process from 'node:process';
|
||||
@@ -7,7 +7,6 @@ import { fileURLToPath } from 'node:url';
|
||||
|
||||
const projectRoot = path.resolve(path.dirname(fileURLToPath(import.meta.url)), '..');
|
||||
const siteSource = path.join(projectRoot, 'pages-dist');
|
||||
const workflowSource = path.join(projectRoot, 'pages', 'deploy.yml');
|
||||
const repository = process.env.GITHUB_PAGES_REPOSITORY ?? 'https://github.com/DD4SN/DD4SN.github.io.git';
|
||||
|
||||
if (!process.env.GITHUB_PAGES_TOKEN) {
|
||||
@@ -54,10 +53,6 @@ try {
|
||||
await cp(siteSource, checkout, { recursive: true });
|
||||
await writeFile(path.join(checkout, '.nojekyll'), '');
|
||||
|
||||
const workflowTarget = path.join(checkout, '.github', 'workflows');
|
||||
await mkdir(workflowTarget, { recursive: true });
|
||||
await cp(workflowSource, path.join(workflowTarget, 'deploy.yml'));
|
||||
|
||||
await requireGit(['config', 'user.name', 'HolodoriCalc deployment'], { cwd: checkout, env: gitEnvironment });
|
||||
await requireGit(['config', 'user.email', 'actions@users.noreply.github.com'], { cwd: checkout, env: gitEnvironment });
|
||||
await requireGit(['add', '--all', '--', '.'], { cwd: checkout, env: gitEnvironment });
|
||||
|
||||
Reference in New Issue
Block a user