fix(ci): restore packages:write for release image push - #2155
Merged
Merged
Conversation
reusable-docker-build-push.yaml gained a top-level permissions block in 8d8851c (Scorecard fix) that only grants contents: read. Reusable workflows do not inherit the caller's job-level permissions once they declare their own block, so packages: write from release-images.yaml is silently dropped, and GHCR push fails with "denied: installation not allowed to Write organization package". Signed-off-by: Mauro Sardara <msardara@cisco.com>
msardara
enabled auto-merge
October 1, 2026 08:12
reusable-docker-build-push.yaml now requests packages: write unconditionally. ci.yaml's docker-build job called it without any packages grant, so GitHub's static reusable-workflow permission check rejected the workflow even though this call path never pushes (push only runs on tag refs). Signed-off-by: Mauro Sardara <msardara@cisco.com>
2 of 4 tasks
muscariello
added a commit
to muscariello/slim
that referenced
this pull request
Oct 5, 2026
The slim-v3.0.0 and slim-v3.0.1 image pushes failed because agntcy#2032 gave the reusable build workflow a top-level permissions block that dropped packages: write. agntcy#2155 restored the grant, but nothing stops the same mistake from coming back, and the failure went unnoticed for days. - reusable-docker-build-push: push and ref are explicit inputs instead of being inferred from the triggering event; grants move to the job; pushed tags are read back from the registry after the push. - release-images: add workflow_dispatch to rebuild an existing tag with the current workflow (re-running a tag run reuses the broken one); latest is opt-in for manual rebuilds; open an issue when a release image build fails; drop the unused attestations: write grant. - lint-workflows: add a check that fails when a reusable workflow drops a write scope its caller grants. It flags the pre-agntcy#2155 tree. Signed-off-by: Luca Muscariello <muscariello@ieee.org>
muscariello
added a commit
to muscariello/slim
that referenced
this pull request
Oct 5, 2026
The slim-v3.0.0 and slim-v3.0.1 image pushes failed with "installation not allowed to Write organization package". agntcy#2032 added a top-level `permissions: contents: read` to the reusable build workflow, and for a reusable workflow that block is the whole list: `packages: write` from the caller became none. agntcy#2155 put the grant back, but the shape that invited the mistake was still there, and nothing exercised the push path between releases, so the breakage surfaced weeks later at release time. - reusable-docker-build-push: keep the top-level block empty and put the grants on the job, next to the steps that need them. Take the token from `github.token` -- a reusable workflow already gets GITHUB_TOKEN with the caller job's grants -- instead of passing it as a secret, and drop that input. `push` and `ref` become explicit inputs rather than being inferred from the triggering event. Read every pushed tag back from the registry, so a green run means pullable images. - ci: push the `main` tag on merges to main. The same login-build-push-verify path a release takes now runs on every merge, on a moving tag that does not accumulate, so a broken grant fails on the commit that caused it. This also covers the gap that ci never passed `github-token`, so its login would have failed on first push. - release-images: add workflow_dispatch to rebuild an existing tag with the current workflow, since re-running a tag run replays the workflow as it was at the tag. `latest` is opt-in for those manual rebuilds. Open an issue when a release image build fails. Drop the unused `attestations: write` grant. Signed-off-by: Luca Muscariello <muscariello@ieee.org>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
reusable-docker-build-push.yamladded a top-levelpermissions: contents: readblock in fix(security): address code scanning alerts #2032 (Scorecard fix for missing explicit permissions).permissions:block no longer inherit the caller's job-level grants for unlisted scopes — they getnone. Since the caller (release-images.yaml) grantspackages: write, but the reusable workflow only listedcontents: read, that write permission was silently dropped.slim-v3.0.1run: https://github.com/agntcy/slim/actions/runs/36715071461) withdenied: installation not allowed to Write organization package, even thoughrelease-images.yamlitself was never changed.packages: writeto the reusable workflow's top-level permissions block so the grant actually reaches the push step.Test plan
slim-*tag) to confirmci-release-imagespushes successfully toghcr.io/agntcy/slim