Workflow-Test [WithManifest] - push [馃 [Fix]: Obsolete GitHub token write permissions removed (#521)
Repositories that use the GitHub App permission model can run
Process-PSModule without granting unneeded repository, pull-request, or
status write access. GitHub Pages deployments continue to use the
caller's github.token with contents: read, pages: write, and
id-token: write.
## Fixed: Reusable workflow permission escalation
The reusable workflow no longer requests permissions that GitHub A...
#1881
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Workflow-Test [WithManifest] | |
| run-name: 'Workflow-Test [WithManifest] - ${{ github.event_name }} [${{ github.event.pull_request.title || github.event.head_commit.message || github.ref_name }}] by @${{ github.actor }}' | |
| on: | |
| workflow_dispatch: | |
| push: | |
| branches: | |
| - main | |
| paths: | |
| - '.github/actions/**' | |
| - '.github/workflows/**' | |
| - 'tests/srcWithManifestTestRepo/**' | |
| - '!.github/workflows/Release.yml' | |
| - '!.github/workflows/Linter.yml' | |
| pull_request: | |
| types: | |
| - closed | |
| - opened | |
| - reopened | |
| - synchronize | |
| - labeled | |
| - unlabeled | |
| paths: | |
| - '.github/actions/**' | |
| - '.github/workflows/**' | |
| - 'tests/srcWithManifestTestRepo/**' | |
| - '!.github/workflows/Release.yml' | |
| - '!.github/workflows/Linter.yml' | |
| schedule: | |
| - cron: '0 0 * * *' | |
| concurrency: | |
| group: ${{ github.workflow }}-${{ github.event.pull_request.number || github.ref }} | |
| cancel-in-progress: false | |
| permissions: | |
| contents: read | |
| pages: write | |
| id-token: write | |
| jobs: | |
| WorkflowTestWithManifest: | |
| if: ${{ github.event_name != 'pull_request' || github.event.pull_request.head.repo.full_name == github.repository }} | |
| uses: ./.github/workflows/workflow.yml | |
| secrets: | |
| PSGALLERY_API_KEY: ${{ secrets.PSGALLERY_API_KEY }} | |
| GitHubAppClientId: ${{ secrets.SHELLY_CLIENT_ID }} | |
| GitHubAppPrivateKey: ${{ secrets.SHELLY_PRIVATE_KEY }} | |
| TestData: >- | |
| { | |
| "secrets": { | |
| "PSMODULE_TEST_SINGLELINE_SECRET": "${{ secrets.PSMODULE_TEST_SINGLELINE_SECRET }}" | |
| }, | |
| "variables": { | |
| "PSMODULE_TEST_VARIABLE": ${{ toJSON(vars.PSMODULE_TEST_VARIABLE) }} | |
| } | |
| } | |
| with: | |
| WorkingDirectory: tests/srcWithManifestTestRepo | |
| ImportantFilePatterns: | | |
| ^tests/srcWithManifestTestRepo/ | |
| ^\.github/actions/ | |
| ^\.github/workflows/(?!Release\.yml$|Linter\.yml$) | |
| VerifyRootFunctionsIndexWithManifest: | |
| name: Verify root Functions index [WithManifest] | |
| runs-on: ubuntu-latest | |
| needs: | |
| - WorkflowTestWithManifest | |
| steps: | |
| - name: Checkout repo | |
| uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 | |
| with: | |
| persist-credentials: false | |
| fetch-depth: 0 | |
| - name: Download docs artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: docs | |
| path: tests/srcWithManifestTestRepo/outputs/docs | |
| - name: Verify root Functions index is published | |
| shell: pwsh | |
| run: | | |
| $path = 'tests/srcWithManifestTestRepo/outputs/docs/index.md' | |
| if (-not (Test-Path -Path $path)) { | |
| throw 'Expected root Functions index at ' + | |
| 'tests/srcWithManifestTestRepo/outputs/docs/index.md.' | |
| } | |
| $content = Get-Content -Path $path -Raw | |
| $expectedSnippets = @( | |
| '# Functions' | |
| 'This landing page is authored from the root of ' + | |
| '`src/functions/public`.' | |
| 'Use it to introduce the module''s function surface ' + | |
| 'before readers drill into each group.' | |
| ) | |
| foreach ($snippet in $expectedSnippets) { | |
| if (-not $content.Contains($snippet)) { | |
| throw 'Expected snippet not found in generated root ' + | |
| "Functions index: $snippet" | |
| } | |
| } |