ci: use DEPLOY_TOKEN secret (GITEA_ prefix is reserved)
ci / verify (push) Successful in 4m3s
ci / publish (push) Failing after 47s

Gitea forbids secret names starting with GITEA_; map the DEPLOY_TOKEN
secret to the GITEA_TOKEN env var consumed by publish.sh.
This commit is contained in:
jdevega
2026-09-15 20:34:56 +02:00
parent cc8e9a23b3
commit 953523e40a
5 changed files with 13 additions and 7 deletions
+3 -2
View File
@@ -49,8 +49,9 @@
## Integration points
- **Gitea Actions** reads `secrets.GITEA_TOKEN` (scope `write:package`) and
`GITEA_OWNER`/`GITEA_URL`; publish job runs only on `main`.
- **Gitea Actions** reads the `DEPLOY_TOKEN` secret (scope `write:package`) and
`GITEA_OWNER`/`GITEA_URL`; publish job runs only on `main`. Secret names must not start with
the reserved `GITEA_` prefix.
- **`scripts/publish.sh`** uploads via `curl` to the generic registry; package names are
prefixed `rule-*` and `gate-*`.
- **Consumer contract**: bundles scope roots to `rules` so operators can supply