mirror of
https://github.com/nlohmann/json.git
synced 2026-10-03 13:10:33 +00:00
The checkout step in publish_documentation.yml left the default persist-credentials: true, so GITHUB_TOKEN stayed writable in .git/config for the rest of the job (zizmor's artipacked finding). The Deploy documentation step authenticates through its own github_token input to peaceiris/actions-gh-pages and does not push with the checked-out credentials, so persist-credentials: false is safe here, matching every other checkout in the workflow set. Overlaps #5638, which edits this same checkout step (adds fetch-depth: 0); expect a rebase conflict there. Part of #5718 item 2 Signed-off-by: Niels Lohmann <mail@nlohmann.me>
58 lines
1.6 KiB
YAML
58 lines
1.6 KiB
YAML
name: Publish documentation
|
|
|
|
# publish the documentation on every merge to develop branch
|
|
on:
|
|
push:
|
|
branches:
|
|
- develop
|
|
paths:
|
|
- docs/mkdocs/**
|
|
# the site also embeds these files via pymdownx.snippets
|
|
# (mkdocs.yml sets restrict_base_path: false for this)
|
|
- .clang-tidy
|
|
- .github/CODE_OF_CONDUCT.md
|
|
- .github/CONTRIBUTING.md
|
|
- .github/SECURITY.md
|
|
- cmake/clang_flags.cmake
|
|
- cmake/gcc_flags.cmake
|
|
- tests/fmt_formatter/project/main.cpp
|
|
- tools/astyle/.astylerc
|
|
workflow_dispatch:
|
|
|
|
# we don't want to have concurrent jobs, and we don't want to cancel running jobs to avoid broken publications
|
|
concurrency:
|
|
group: documentation
|
|
cancel-in-progress: false
|
|
|
|
permissions:
|
|
contents: read
|
|
|
|
jobs:
|
|
publish_documentation:
|
|
permissions:
|
|
contents: write
|
|
|
|
if: github.repository == 'nlohmann/json'
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- name: Harden Runner
|
|
uses: step-security/harden-runner@e14015d583714f6e62063499dc959a02595150a1 # v2.21.1
|
|
with:
|
|
egress-policy: audit
|
|
|
|
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
|
with:
|
|
persist-credentials: false
|
|
|
|
- name: Install virtual environment
|
|
run: make install_venv -C docs/mkdocs
|
|
|
|
- name: Build documentation
|
|
run: make build -C docs/mkdocs
|
|
|
|
- name: Deploy documentation
|
|
uses: peaceiris/actions-gh-pages@84c30a85c19949d7eee79c4ff27748b70285e453 # v4.1.0
|
|
with:
|
|
github_token: ${{ secrets.GITHUB_TOKEN }}
|
|
publish_dir: ./docs/mkdocs/site
|