Skip to content

Commit 594ed39

Browse files
fix(ci): gate release and package-deletion jobs behind release environment (#222)
Both the release job and the delete-packages-and-releases job could run without any approval gate, even though the destructive delete workflow is directly dispatchable and is also invoked by release.yml. Adding `environment: release` to each job routes them through the existing `release` GitHub Environment, which already has required reviewers and a branch policy configured. Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent d761a2e commit 594ed39

2 files changed

Lines changed: 2 additions & 0 deletions

File tree

‎.github/workflows/delete-packages-and-releases.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@ permissions:
2323
jobs:
2424
delete:
2525
name: Delete packages and releases
26+
environment: release
2627
permissions:
2728
contents: write # for gh release delete and tag cleanup
2829
packages: write # for deleting npm package versions

‎.github/workflows/release.yml‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -63,6 +63,7 @@ jobs:
6363
if: inputs.dev == true
6464
release:
6565
name: Release
66+
environment: release
6667
permissions:
6768
id-token: write # allows this job to request a GitHub OIDC token
6869
contents: write # for git tag push and creating the GitHub release

0 commit comments

Comments
 (0)