From 4d46fe01d2ce5cc0ecaf265ead237119e8ffcd46 Mon Sep 17 00:00:00 2001 From: martinfrancois Date: Mon, 21 Sep 2026 05:31:23 +0200 Subject: [PATCH] ci: publish with verified provenance The java-functional-style 0.1.0 publish run warned that the job cannot read a GitHub OIDC token, so plugins go out without verified provenance; this workflow has the same permissions block. The publish job now requests id-token: write. --- .github/workflows/publish-tessl.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/publish-tessl.yml b/.github/workflows/publish-tessl.yml index 26f7b2a..1741ea0 100644 --- a/.github/workflows/publish-tessl.yml +++ b/.github/workflows/publish-tessl.yml @@ -17,6 +17,7 @@ on: permissions: contents: read + id-token: write concurrency: group: publish-tessl-${{ github.event.release.tag_name || inputs.ref || github.ref }}