Skip to content

ci: scope release env and OIDC permissions to main - #47

Merged
bdraco merged 1 commit into
mainfrom
ci/scope-release-permissions
Jun 22, 2026
Merged

bdraco merged 1 commit into
mainfrom
ci/scope-release-permissions

Conversation

@bdraco

@bdraco bdraco commented Jun 22, 2026 •

Copy link
Copy Markdown
Member

Summary

The release job held id-token: write, contents: write, and the release environment on every trigger including pull requests, even though it only published on main; this splits it into two jobs so PR runs no longer carry release credentials.

Details

release-dry-run runs on PRs and non-main pushes with only contents: read, no environment and no OIDC, just the python-semantic-release dry run; release runs only on main and keeps the release environment plus write and OIDC permissions scoped to that job, so they never apply to untrusted PR code.

Test plan

  • workflow YAML parses clean
  • dry-run job runs on this PR, publish job stays skipped

Summary by CodeRabbit

  • Chores
    • Improved release automation workflow with enhanced dry-run validation for pull requests and non-main branches.
    • Refined permissions scoping and concurrency management for production releases.

@coderabbitai

coderabbitai Bot commented Jun 22, 2026 •

Copy link
Copy Markdown

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 684fa1be-757d-4aa8-85ee-937c457f1c99

📥 Commits

Reviewing files that changed from the base of the PR and between 834aeac and 6b33f61.

📒 Files selected for processing (1)
  • .github/workflows/ci.yml

📝 Walkthrough

Walkthrough

The CI workflow splits release logic into two separate jobs: a new release-dry-run job that runs python-semantic-release in --noop mode on non-main refs, and a refactored release job gated at the job level to main only. Branch creation logic is updated to use github.ref_name throughout.

Changes

CI Release Job Restructure

Layer / File(s) Summary
release-dry-run job, release job gating, and branch logic
.github/workflows/ci.yml
Adds release-dry-run job with --noop flag, if: github.ref_name != 'main' gate, and dependencies on test, lint, commitlint. Updates release job to use a job-level if: github.ref_name == 'main' condition, changes concurrency group to release-${{ github.ref }}, and replaces the prior step-level conditional with job-level gating. Checkout and git switch commands inside release are updated to use github.ref_name instead of the prior combined expression.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

A rabbit hops through pipelines bright,
Dry-runs on branches, safe from fright,
Only on main does the real release fly,
With ref_name guiding through the CI sky,
No more step-level checks—jobs split just right! 🐇✨

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch ci/scope-release-permissions

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@bdraco
bdraco marked this pull request as ready for review June 22, 2026 01:17
@bdraco
bdraco merged commit bb5752a into main Jun 22, 2026
8 of 9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant