From 6b33f61499498d974256a35579bec5d12102fcd8 Mon Sep 17 00:00:00 2001 From: "J. Nick Koston" Date: Sun, 21 Jun 2026 20:14:17 -0500 Subject: [PATCH] ci: scope release env and OIDC permissions to main --- .github/workflows/ci.yml | 46 ++++++++++++++++++++++++++++++---------- 1 file changed, 35 insertions(+), 11 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 825b48a..b5c5b7f 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -63,15 +63,43 @@ jobs: - name: 🚀 Run pytest run: poetry run pytest --cov src tests - release: + # Dry run on PRs and non-main pushes. No environment, no publish + # permissions, no OIDC, so PR runs carry no release blast radius. + release-dry-run: needs: - test - lint - commitlint + if: github.ref_name != 'main' + runs-on: ubuntu-latest + permissions: + contents: read + steps: + - uses: actions/checkout@v4 + with: + fetch-depth: 0 + ref: ${{ github.ref }} + - name: Create local branch name + env: + BRANCH: ${{ github.head_ref || github.ref_name }} + run: git switch -C "$BRANCH" + - name: Test release + uses: python-semantic-release/python-semantic-release@v9.8.1 + with: + root_options: --noop + # Real release, only on main. The release environment and write/OIDC + # permissions are scoped to this job so they never apply to PR runs. + release: + needs: + - test + - lint + - commitlint + if: github.ref_name == 'main' runs-on: ubuntu-latest environment: release - concurrency: release + concurrency: + group: release-${{ github.ref }} permissions: id-token: write contents: write @@ -80,20 +108,16 @@ jobs: - uses: actions/checkout@v4 with: fetch-depth: 0 - ref: ${{ github.head_ref || github.ref_name }} - - # Do a dry run of PSR - - name: Test release - uses: python-semantic-release/python-semantic-release@v9.8.1 - if: github.ref_name != 'main' - with: - root_options: --noop + ref: ${{ github.ref_name }} + - name: Create local branch name + env: + BRANCH: ${{ github.ref_name }} + run: git switch -C "$BRANCH" # On main branch: actual PSR + upload to PyPI & GitHub - name: Release uses: python-semantic-release/python-semantic-release@v9.8.1 id: release - if: github.ref_name == 'main' with: github_token: ${{ secrets.GITHUB_TOKEN }}