Skip to content

ci: use gh CLI to attach .deb to release - #5

Merged
ghjklw merged 1 commit into
mainfrom
fix/deb-release-gh-cli
Sep 1, 2026
Merged

ghjklw merged 1 commit into
mainfrom
fix/deb-release-gh-cli

Conversation

@simukka

@simukka simukka commented Sep 1, 2026

Copy link
Copy Markdown

Problem

The Build .deb package workflow fails at the release step:

The action softprops/action-gh-release@v2 is not allowed in vippsas/i3lock because all actions must be from a repository owned by your enterprise, created by GitHub, or match one of the allowed patterns.

Fix

Replace the disallowed third-party action with the gh CLI, which is preinstalled on GitHub-hosted runners and requires no allow-listing.

  • Creates the release if it doesn't exist yet, tolerating the race between the two matrix jobs (ubuntu-22.04 / ubuntu-24.04).
  • Uploads each package with gh release upload --clobber so both matrix packages attach to the same tag and re-runs are idempotent.
  • Uses github.token; the existing contents: write permission is sufficient.

No other workflow references the disallowed action.

Replace softprops/action-gh-release@v2, which is disallowed by the
enterprise Actions policy, with the preinstalled gh CLI. Creates the
release if missing (tolerating the race between matrix jobs) and uploads
each package with --clobber for idempotent re-runs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
@simukka
simukka requested a review from a team as a code owner September 1, 2026 12:19
@ghjklw
ghjklw merged commit 149baa7 into main Sep 1, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants