v1.13.1
What's Changed
- fix(go-binary-release): grant packages: write so GHCR pushes can succeed by @juicycleff in #1
Why
go-binary-release.yml's goreleaser job declared permissions: contents: write and nothing else. Once a permissions: block exists, everything unlisted is none — so GITHUB_TOKEN had packages: none, while the docker: true path logs into the registry as exactly that token and then pushes. Releases built fully and then failed at the last step with:
denied: installation not allowed to Write organization package
That message reads like a registry ACL problem and is not one: the token had no packages scope to exercise, so granting a repository write access on the GHCR package changed nothing.
Callers could not work around it either — a reusable workflow's own permissions: block is authoritative for its jobs, so a caller declaring packages: write on the calling job had no effect, and GORELEASER_TOKEN never reaches the login step, which hardcodes secrets.GITHUB_TOKEN.
Harmless when docker is false: nothing authenticates to a registry on that path, so the scope goes unused.
For callers pinned at @v1
The v1 tag has been moved to this commit, so uses: xraph/workflows/.github/workflows/go-binary-release.yml@v1 picks this up on the next run — no change needed on your side.
Full Changelog: v1.13.0...v1.13.1