From f1842fcbabe2a5a9a0ef22818e1290aa73e24b68 Mon Sep 17 00:00:00 2001 From: Simone Date: Sat, 15 Aug 2026 01:46:59 +0200 Subject: [PATCH] fix: restrict self-hosted release workflow to tags --- .github/workflows/self-hosted-release.yml | 5 +---- tests/contract/release/self-hosted-matrix.test.ts | 3 ++- 2 files changed, 3 insertions(+), 5 deletions(-) diff --git a/.github/workflows/self-hosted-release.yml b/.github/workflows/self-hosted-release.yml index bc27775..5ce2ee8 100644 --- a/.github/workflows/self-hosted-release.yml +++ b/.github/workflows/self-hosted-release.yml @@ -1,7 +1,6 @@ name: Self-hosted release on: - workflow_dispatch: push: tags: - "self-hosted-v*" @@ -15,9 +14,7 @@ env: jobs: certified-matrix: - if: - startsWith(github.ref, 'refs/tags/self-hosted-v') || github.event_name == - 'workflow_dispatch' + if: startsWith(github.ref, 'refs/tags/self-hosted-v') strategy: fail-fast: false matrix: diff --git a/tests/contract/release/self-hosted-matrix.test.ts b/tests/contract/release/self-hosted-matrix.test.ts index 23b0349..8d07554 100644 --- a/tests/contract/release/self-hosted-matrix.test.ts +++ b/tests/contract/release/self-hosted-matrix.test.ts @@ -142,7 +142,7 @@ describe("Feature 004 certified release matrix", () => { expect(workflowSource).toContain("actual-release-assets.txt"); }); - it("pins every action and exposes no privileged pull-request release event", async () => { + it("pins every action and exposes no privileged non-tag release event", async () => { const workflowSource = await readFile( ".github/workflows/self-hosted-release.yml", "utf8", @@ -152,6 +152,7 @@ describe("Feature 004 certified release matrix", () => { ); expect(uses.length).toBeGreaterThan(0); expect(uses.every((use) => /@[0-9a-f]{40}$/.test(use))).toBe(true); + expect(workflowSource).not.toMatch(/^ workflow_dispatch:/mu); expect(workflowSource).not.toMatch(/^\s+pull_request(?:_target)?:/mu); expect(workflowSource).not.toContain("pull-requests: write"); });