Merge pull request #637 from AIOSAI/dev

security(ci): least-privilege token on e2e-wheel workflow + W24 changelog (also carries playbook commit 6b89fcd)
This commit is contained in:
AIPass
2026-06-08 10:36:14 -07:00
committed by GitHub
6 changed files with 50 additions and 6 deletions
+5
View File
@@ -23,6 +23,11 @@ on:
- "src/**"
workflow_dispatch:
# Least-privilege token (Scorecard Token-Permissions). This workflow only
# reads the repo to build + smoke-test the wheel; it needs no write scopes.
permissions:
contents: read
jobs:
e2e-wheel:
name: e2e-wheel (${{ matrix.os }})
+12
View File
@@ -41,12 +41,24 @@ jobs:
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write # keyless Sigstore signing (OIDC); no signing key exists
steps:
- uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3
- uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: dist
path: dist/
- name: Sign artifacts with Sigstore (keyless, OIDC)
# Produces dist/<artifact>.sigstore.json bundles next to each wheel/sdist.
# The 'gh release create dist/*' step below then attaches them to the
# GitHub Release, which is where Scorecard's Signed-Releases check looks.
# release-signing-artifacts is disabled: the action's own auto-attach only
# fires on a 'release: published' event, but we trigger on 'push: tags',
# so we upload the bundles ourselves via the dist/* glob.
uses: sigstore/gh-action-sigstore-python@04cffa1d795717b140764e8b640de88853c92acc # v3.3.0
with:
inputs: ./dist/*.tar.gz ./dist/*.whl
release-signing-artifacts: false
- name: Extract latest CHANGELOG section
run: |
# Grab the topmost "## [...]" block from CHANGELOG.md as release notes.