Skip to content

Document Mix fetching with organization workload identities and reword the Workload Identity docs - #2022

Merged
ericmj merged 2 commits into
mainfrom
ericmj/workload-identity-fetch-docs
Oct 10, 2026
Merged

ericmj merged 2 commits into
mainfrom
ericmj/workload-identity-fetch-docs

Conversation

@ericmj

@ericmj ericmj commented Oct 10, 2026

Copy link
Copy Markdown
Member

When Mix fetches packages from an organization's repository in a GitHub Actions job with the id-token: write permission, and neither an organization key nor an authenticated user is configured, it exchanges the job's OIDC token for a repository token (hexpm/hex#1266). The organization section of the Workload Identity guide now says so, and the limitation saying Mix doesn't request repository tokens is removed.

The Workload Identity guide and its paragraph in the publishing guide are reworded without changing the facts: sentences joined by semicolons are split, sentences in the passive voice name who does what, negations use contractions, the empty-field list drops its bold lead-ins, and phrases like "publish-oriented", "land the first release" and "put a gate in front of a publish" are replaced with what they mean.

Split sentences joined by semicolons, name who does what instead of
using the passive voice, use contractions, drop the bold lead-ins from
the empty-field list and replace phrasing like "publish-oriented",
"land the first release" and "put a gate in front of a publish" with
what it means. The facts are unchanged.
When Mix fetches packages from an organization's repository in a GitHub
Actions job with the id-token: write permission, and neither an
organization key nor an authenticated user is configured, it exchanges
the job's OIDC token for a repository token
(hexpm/hex#1266). Say so in the organization
section and remove the limitation saying it doesn't.
@github-actions

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA a781bc0.
Ensure that dependencies are being submitted on PR branches. Re-running this action after a short time may resolve the issue. See the documentation for more information and troubleshooting advice.

Scanned Files

None

@ericmj
ericmj merged commit b4fcc81 into main Oct 10, 2026
18 checks passed
@ericmj
ericmj deleted the ericmj/workload-identity-fetch-docs branch October 10, 2026 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant