ci: publish with verified provenance - #91
Merged
Merged
Conversation
The java-functional-style 0.1.0 publish run warned that the job cannot read a GitHub OIDC token, so plugins go out without verified provenance; this workflow has the same permissions block. The publish job now requests id-token: write.
martinfrancois
force-pushed
the
ci/publish-provenance
branch
from
September 21, 2026 04:27
3285a3e to
4d46fe0
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tessl plugin publishin the java-functional-style-skill 0.1.0 release run (GitHub Actions run 35557635462 in that repository) warned "This job cannot read a GitHub OIDC token. This publish will go out without verified provenance."permissions:block in.github/workflows/publish-tessl.ymlgainsid-token: writenext tocontents: read. The workflow has one job, so the grant reaches the step that runstessl plugin publish .. No action input is needed; the CLI reads the token itself, and the setup-tessl README's publish example uses exactly these two permissions.ci.ymlruns on pull requests, where widening permissions is not wanted).Change Type
Linked Issue
User-Visible Behavior
None. Future releases publish with verified provenance.
Bug Fix Details
permissions:block replaces GitHub's defaults and did not includeid-token.Validation
Checks most contributors can run:
bash -n scripts/*.sh-> passedpython3 -m py_compile scripts/*.py-> passedpython3 scripts/validate_json_files.py-> passedpython3 scripts/validate_openai_agent_yaml.py-> passedpython3 scripts/validate_skill.py skills/java-streams-> passedpython3 scripts/validate_eval_criteria.py evals evals-reference evals-regression-> passed, 29 scenariostessl plugin lint .-> passednpx js-yaml .github/workflows/publish-tessl.yml-> parses;permissionsis{contents: read, id-token: write}Tessl-authenticated checks:
docs/agents/workflow.mdlists the publish dry-runs for CI changes; a permission line changes no package content, so they would show nothing new.Details:
Human Verification
Review Checklist
docs/agents/workflow.md, or any Tessl blocker is documented. (Not changed.)AI Assistance (if used)
AI prompts / session logs (optional)