Skip to content

fix(ci): add id-token write permission for Infisical OIDC - #37

Merged
ajianaz merged 1 commit into
developfrom
fix/oidc-permission
May 30, 2026
Merged

ajianaz merged 1 commit into
developfrom
fix/oidc-permission

Conversation

@ajianaz

@ajianaz ajianaz commented May 30, 2026 •

Copy link
Copy Markdown
Collaborator

Publish job failed: 'Unable to get ACTIONS_ID_TOKEN_REQUEST_URL env variable'

Root cause: missing permissions: id-token: write on publish-crates job. OIDC token exchange requires this permission.

Summary by CodeRabbit

This PR contains no user-facing changes. It updates internal CI/CD workflow configuration to enhance security permissions for the release process. No new features, bug fixes, or changes visible to end-users have been introduced.

Review Change Stack

@ajianaz
ajianaz merged commit d67613c into develop May 30, 2026
@coderabbitai

coderabbitai Bot commented May 30, 2026 •

Copy link
Copy Markdown

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: eb9f4eda-2788-4987-84c1-fbc605a62485

📥 Commits

Reviewing files that changed from the base of the PR and between 8e6cc5d and b73b1b0.

📒 Files selected for processing (1)
  • .github/workflows/release.yml

📝 Walkthrough

Walkthrough

This PR adds explicit OIDC token write permissions to the publish-crates job in the release workflow, enabling the Infisical secrets-fetch step to authenticate and retrieve credentials during the publishing process.

Changes

Workflow Job OIDC Permissions

Layer / File(s) Summary
OIDC Token Permission Grant
.github/workflows/release.yml
The publish-crates job declares permissions: id-token: write, granting explicit GitHub Actions OIDC token authorization for the secrets-fetch step.

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~3 minutes

Poem

🐰 A token whispers in the GitHub night,
Permissions granted, secrets shining bright,
Infisical awakens with a gentle sign,
Publishing crates flows through the line,
One small change makes the workflow shine! 🎀

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/oidc-permission

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@ajianaz
ajianaz deleted the fix/oidc-permission branch May 30, 2026 10:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant