docs: record the fork-only environment gate in RFC 0002 - #98
Merged
Conversation
The vite-plus implementation runs the publish job in a GitHub environment, a control the RFC never described. vite-plus#2404 narrowed that gate to fork PRs: preview-build-release (required reviewers) for forks, preview-build-release-auto (no protection rules) for same-repo PRs, which publish unattended once labeled. Record the gate in the section 7 workflow sketch and details, explain its fork-only scope in 8.1, and note the unattended same-repo publish in the 8.4 triage-permission risk.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The vite-plus implementation runs the
publishjob in a GitHub environment, a control RFC 0002 never described. voidzero-dev/vite-plus#2404 narrowed that gate to fork PRs:preview-build-release(required reviewers) for forks,preview-build-release-auto(no protection rules) for same-repo PRs, which publish unattended once labeled.Changes:
environment:expression on thepublishjob, keyed on a newis-forkoutput fromauthorizeauthorizeregresses; same-repo PRs skip it because the label binds consent to the exact built sha