ci: harden workflow release guards#10
Conversation
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Pro Plus Run ID: 📒 Files selected for processing (3)
📝 WalkthroughWalkthroughThree GitHub Actions workflows are updated to improve security and release automation control. Workflow token permissions are restricted to least-privilege levels. Release publishing steps are guarded to execute only when triggered by git tags, and a verification step is added before tag creation. ChangesWorkflow Security and Release Automation
Estimated code review effort🎯 2 (Simple) | ⏱️ ~10 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
Validation
Summary by CodeRabbit