diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 3f82088..ef91e3c 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -155,11 +155,20 @@ jobs: contents: write steps: + - name: Validate release token + env: + RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }} + run: | + if [ -z "$RELEASE_TOKEN" ]; then + echo "::error::RELEASE_TOKEN is required for git_ops.release so release commits and tags trigger follow-up workflows." + echo "::error::Configure RELEASE_TOKEN as a least-privilege service account PAT, or replace it with a GitHub App installation token." + exit 1 + fi + - name: Checkout uses: actions/checkout@v6 with: fetch-depth: 0 # Need full history for git_ops - # Use PAT to bypass branch protection rules token: ${{ secrets.RELEASE_TOKEN }} - name: Setup Elixir