Skip to content

fix(ci): Trim Features permissions and allow manual publish - #7

Merged
leocavalcante merged 2 commits into
mainfrom
fix/features-ghcr-access
Sep 29, 2026
Merged

leocavalcante merged 2 commits into
mainfrom
fix/features-ghcr-access

Conversation

@leocavalcante

Copy link
Copy Markdown
Member

Summary

  • Drop pull-requests: write from the Features workflow; generate-docs is off and the official devcontainers/features release workflow only grants packages: write and contents: write.
  • Add workflow_dispatch so publish can be re-run after GHCR package Actions access is fixed, without another code push.

Why Features still failed on main after #5

PR #5 correctly switched to secrets.GITHUB_TOKEN and granted job permissions. The post-merge run (36619966172) authenticated enough to read versions, then failed on upload with:

Server did not provide instructions to authentiate! (Required: A 'WWW-Authenticate' Header)

That matches GHCR packages that were first published with a PAT and never granted Actions access to this repository. Workflow YAML cannot fix that alone.

Required org/package step (before merge or right after)

For both packages:

  • ghcr.io/opencodeco/devcontainers/install-php-extensions
  • ghcr.io/opencodeco/devcontainers (collection metadata)

Package settings → Manage Actions access → add opencodeco/devcontainers with Write.

Alternatively delete both packages so the next GITHUB_TOKEN publish recreates them linked to this repo.

Settings: https://github.com/orgs/opencodeco/packages/container/devcontainers%2Finstall-php-extensions/settings

Test plan

  • Grant Actions Write on both GHCR packages (or delete them)
  • Merge this PR or run Features via workflow_dispatch
  • Confirm Features on main publishes successfully

Match the official features publish workflow permissions, and add
workflow_dispatch so GHCR publish can be retested after package Actions
access is granted.
@leocavalcante
leocavalcante requested a balanced review from Copilot September 29, 2026 19:52
@leocavalcante leocavalcante self-assigned this Sep 29, 2026
@leocavalcante leocavalcante added the bug Something isn't working label Sep 29, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Manual publishing must be restricted to main to prevent releases from unmerged branches.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Updates feature publishing permissions and enables manual reruns.

Changes:

  • Removes unnecessary pull-request write access.
  • Adds manual workflow dispatch.
File Description
.github/​workflows/​features.yml Adjusts permissions and adds manual publishing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/features.yml
@leocavalcante
leocavalcante requested a balanced review from Copilot September 29, 2026 19:53

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

Manual publishing is safely branch-restricted and permissions match the upstream release workflow.

Review effort: Balanced
Findings: None

Resolved since last review (1)

@leocavalcante
leocavalcante merged commit 6265a54 into main Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants