Files
ansible-role-sudo/.gitea/workflows/release.yaml
T
volker.raschekandCopilot ee977a8610 fix(ci): pin actions to their commit sha
Floating tags let a compromised or force pushed release change what the workflows execute. Pinning the actions to a
commit sha and restricting the default token to read access limits the blast radius of a supply chain attack. The
outdated ansible-lint and markdownlint-cli2 versions are raised along with the pinning.

The ansible-lint run installs the collections of the molecule scenario, because the scenario is linted as well and
depends on community.docker beside the community.general requirement of the role.

Co-authored-by: Copilot <copilot@github.com>
2026-09-10 21:41:34 +02:00

25 lines
555 B
YAML

name: Release Ansible Role
on:
push:
tags:
- '**'
workflow_dispatch: {}
permissions:
contents: read
jobs:
release:
name: Release Ansible Role
runs-on: ubuntu-latest
steps:
- name: Install Ansible Galaxy
run: |
apt update --yes
apt install --yes ansible
- env:
ANSIBLE_GALAXY_TOKEN: ${{ secrets.ANSIBLE_GALAXY_TOKEN }}
name: Update Ansible Role in Ansible Galaxy
run: |
ansible-galaxy role import --token=${ANSIBLE_GALAXY_TOKEN} volker-raschek ${GITHUB_REPOSITORY#*/}