ci: add id-token permission to release-please workflow BM-1462#3589
Merged
tawera-manaena merged 3 commits intomasterfrom Dec 16, 2025
Merged
ci: add id-token permission to release-please workflow BM-1462#3589tawera-manaena merged 3 commits intomasterfrom
tawera-manaena merged 3 commits intomasterfrom
Conversation
Wentao-Kuang
previously approved these changes
Dec 16, 2025
blacha
approved these changes
Dec 16, 2025
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
Our release-please GitHub Action does not have permission to deploy to NPM securely.
Modifications
.github/workflows
release-please.ymlAdded the
id-token: writepermission to the workflow file.Adjusted some permissions and re-structured the file to mirror the release-please workflow file in the lambda-js repository.
Verification
We will know whether this change works if the workflow can publish to NPM without issue by way of a
prodrelease.