fix: disable implicit publishing by default [breaking]#9476
Open
biw wants to merge 6 commits intoelectron-userland:masterfrom
Open
fix: disable implicit publishing by default [breaking]#9476biw wants to merge 6 commits intoelectron-userland:masterfrom
biw wants to merge 6 commits intoelectron-userland:masterfrom
Conversation
fix: skip Netlify PR deploy workflow on forks
Remove automatic publish detection based on CI environment, git tags, and npm lifecycle events. Publishing must now be explicitly requested via the --publish CLI flag or configuration. This is a breaking change that addresses the security and usability concerns raised in electron-userland#5463 where unexpected auto-publishing could accidentally expose secrets or publish unfinished work. BREAKING CHANGE: Publishing no longer happens automatically in CI. Use --publish flag explicitly (e.g., --publish always, --publish onTag). Fixes electron-userland#5463
🦋 Changeset detectedLatest commit: 7355170 The changes in this PR will be included in the next version bump. This PR includes changesets to release 8 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
Collaborator
|
Thanks for prepping the multi-step set of PRs! Love the change. |
Contributor
Author
|
Happy I could help! On the test falure, is there a easy way to fix them / verify they aren't false positives? |
Collaborator
|
Looks like it was a transitive dependency in the node_modules collector fixtures that had a file added, so it was causing the tests to fail suddenly (no changes to Just pushed the change and updated the relevant PRs to latest |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Remove automatic publish detection based on CI environment, git tags, and npm lifecycle events. Publishing must now be explicitly requested via the
--publishCLI flag or configuration.This is a breaking change that addresses the security and usability concerns raised in #5463.
BREAKING CHANGE: Publishing no longer happens automatically in CI. Use
--publishflag explicitly (e.g.,--publish always,--publish onTag).This is designed to be merged in version 27, and #9475 is the warning for the next patch version.