Skip to content

fix(ci): Publish features with the workflow token - #5

Merged
leocavalcante merged 1 commit into
mainfrom
fix/ci-failures
Sep 29, 2026
Merged

leocavalcante merged 1 commit into
mainfrom
fix/ci-failures

Conversation

@leocavalcante

Copy link
Copy Markdown
Member

Summary

  • Feature publish on main fails with GHCR 401 because .github/workflows/features.yml passes secrets.GH_TOKEN. That token is rejected as unauthenticated.
  • The job now uses secrets.GITHUB_TOKEN and grants packages: write, contents: write, and pull-requests: write, which devcontainers/action requires to publish.
  • This does not change the install-php-extensions feature.

Test plan

  • PyYAML loaded .github/workflows/features.yml and checked the token and permissions
  • bash tests/install-php-extensions.sh
  • shellcheck -x on features/install-php-extensions/install.sh and tests/install-php-extensions.sh
  • The CI workflow on this pull request is green
  • After merge, the Features workflow on main publishes to ghcr.io without a 401. That job only runs on push to main, so this pull request cannot rerun it

@leocavalcante leocavalcante added the bug Something isn't working label Sep 29, 2026
@leocavalcante leocavalcante self-assigned this Sep 29, 2026
@leocavalcante
leocavalcante merged commit f088b84 into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant