From 9fd4ce0b1ef3790c8c7ab1b3468a7b2280dd822e Mon Sep 17 00:00:00 2001 From: Doug Eubanks Date: Fri, 25 Sep 2026 17:37:22 -0400 Subject: [PATCH] Stop syncing the Docker Hub description from CI peter-evans/dockerhub-description PATCHes the repository endpoint, which Docker Hub rejects for a repo:write token. Verified on solarham run 36191394041: login and "Build and push" both succeeded, the image published with provenance attested, and only this step returned "Forbidden". Making it work requires repo:admin. Docker Hub has no per-repository scoping for individual accounts, so repo:admin grants Read, Write and DELETE across every image repository on the account. Giving CI the ability to destroy published images so a README stays in sync is the wrong trade, and the point of the credential rotation this accompanies was to remove exactly that. The source markdown stays in the repo. Update the Docker Hub page by hand, or locally with an admin token that never enters CI. A comment at the removal site records why, so it is not re-added and silently made to need admin again. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01SGfGnXm7Bc5MNgwyV4sjT4 --- .github/workflows/release.yml | 23 ++++++++++++++--------- 1 file changed, 14 insertions(+), 9 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 8e0642c..a073fbf 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -52,15 +52,20 @@ jobs: cache-from: type=gha cache-to: type=gha,mode=max - - name: Sync Docker Hub repository description - # Pushes DOCKER_HUB_README.md (repo root) to the Docker Hub repo page. - # Reuses the same Docker Hub credentials used for the image push above. - uses: peter-evans/dockerhub-description@1b9a80c056b620d92cedb9d9b5a223409c68ddfa # v5.0.0 - with: - username: ${{ secrets.DOCKERHUB_USERNAME }} - password: ${{ secrets.DOCKERHUB_TOKEN }} - repository: dougeubanks/gitpreserver - readme-filepath: ./DOCKER_HUB_README.md + # The Docker Hub description is NOT synced from CI, deliberately. + # + # peter-evans/dockerhub-description PATCHes the repository endpoint, and + # Docker Hub rejects that for a repo:write token — verified on solarham + # run 36191394041, where login and the image push both succeeded and only + # this step returned "Forbidden". It needs repo:admin. + # + # repo:admin means Read, Write AND DELETE on every image repository in + # the account, because Docker Hub has no per-repository scoping for + # individual accounts. Granting CI the ability to destroy published + # images so a README stays in sync is the wrong trade. + # + # Update the Docker Hub page by hand, or locally with an admin token that + # never enters CI. DOCKER_HUB_README.md remains the source text. - name: Extract release notes from CHANGELOG.md id: notes