Skip to content

ci: only let the internal repo's main branch publish here - #88

Merged
elham-saboori merged 1 commit into
mainfrom
ci/narrow-publish-allowlist
Sep 28, 2026
Merged

elham-saboori merged 1 commit into
mainfrom
ci/narrow-publish-allowlist

Conversation

@elham-saboori

Copy link
Copy Markdown
Contributor

Narrows .github/allowed-remote-repos.yaml from publish-to-public.yml@.* to publish-to-public.yml@refs/heads/main. The publish from the internal source repo is proven (#87), so only its main branch needs a token to open PRs here. A run from any other branch can no longer get write access to this repo.

Pairs with the internal change that publishes automatically on every merge to main.

🤖 Generated with Claude Code

The publish from unity/skills is proven (#87), so the allowlist no longer
needs to accept a run from any branch. Narrow it to refs/heads/main.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@elham-saboori
elham-saboori marked this pull request as ready for review September 28, 2026 19:47
@elham-saboori
elham-saboori requested a review from a team as a code owner September 28, 2026 19:47
@elham-saboori
elham-saboori merged commit 0c80585 into main Sep 28, 2026
3 checks passed
@elham-saboori
elham-saboori deleted the ci/narrow-publish-allowlist branch September 28, 2026 19:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants