From 53150f496253a5a053608ea63ded5cd264fc303e Mon Sep 17 00:00:00 2001 From: Taylor Becker Date: Wed, 22 Jul 2026 12:55:37 -0400 Subject: [PATCH 1/2] Fix: Authenticate release workflow via SSH deploy key instead of stale PAT The release-workflow checkout used a personal access token (secrets.PAT) that had gone stale, causing 'terminal prompts disabled' failures on fetch. Switch to a repo-scoped SSH deploy key (secrets.COMMIT_KEY) with write access, loaded via webfactory/ssh-agent so axion-release can push the release tag/commit over SSH. Also drops the DEPLOY_KEY env var, which nothing in axion-release-plugin actually reads. --- .github/workflows/release-workflow.yml | 9 ++++----- CHANGELOG.md | 3 +++ 2 files changed, 7 insertions(+), 5 deletions(-) diff --git a/.github/workflows/release-workflow.yml b/.github/workflows/release-workflow.yml index 7279653..836d462 100644 --- a/.github/workflows/release-workflow.yml +++ b/.github/workflows/release-workflow.yml @@ -23,16 +23,15 @@ jobs: steps: - uses: actions/checkout@v4 with: - token: "${{ secrets.PAT }}" + ssh-key: "${{ secrets.COMMIT_KEY }}" fetch-depth: 0 + - uses: webfactory/ssh-agent@v0.10.0 + with: + ssh-private-key: ${{ secrets.COMMIT_KEY }} - uses: gradle/actions/setup-gradle@v6 - name: Gradle Release if: ${{ inputs.versionIncrementer == 'default' }} - env: - DEPLOY_KEY: ${{ secrets.COMMIT_KEY }} run: ./gradlew release - name: Gradle Release w/ Increment Override if: ${{ inputs.versionIncrementer != 'default' }} - env: - DEPLOY_KEY: ${{ secrets.COMMIT_KEY }} run: ./gradlew release -Prelease.versionIncrementer=${{ inputs.versionIncrementer }} diff --git a/CHANGELOG.md b/CHANGELOG.md index 1af5e74..fe9ebf1 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -14,6 +14,9 @@ - Update CI actions (checkout, artifact, setup-gradle, git-release) and runner image - Automate CHANGELOG release patching with the `org.jetbrains.changelog` plugin +### Fixed +- Release workflow authenticates via an SSH deploy key (`COMMIT_KEY`) instead of a stale PAT + ## [0.2.0] - 2022-11-27 ### Added - Separate publish and release creation action workflows From 3a61b3221b79dc98c6614d3597ea9956a0c04b37 Mon Sep 17 00:00:00 2001 From: Taylor Becker Date: Wed, 22 Jul 2026 13:02:57 -0400 Subject: [PATCH 2/2] Fix: Bump actions/checkout to v7 v4 was several majors behind current (v7.0.1). Verified our fetch-depth and ssh-key usage is unaffected by the intervening breaking changes (Node 24 runtime bump in v5/v6, fork-PR checkout restriction in v7 that only applies to pull_request_target/workflow_run triggers, neither of which this workflow uses). --- .github/workflows/release-workflow.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/release-workflow.yml b/.github/workflows/release-workflow.yml index 836d462..358aa75 100644 --- a/.github/workflows/release-workflow.yml +++ b/.github/workflows/release-workflow.yml @@ -21,7 +21,7 @@ jobs: outputs: version: ${{ steps.version.outputs.version }} steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 with: ssh-key: "${{ secrets.COMMIT_KEY }}" fetch-depth: 0