Skip to content

docs: record the fork-only environment gate in RFC 0002 - #98

Merged
fengmk2 merged 1 commit into
mainfrom
rfc-0002-fork-only-gate
Aug 13, 2026
Merged

docs: record the fork-only environment gate in RFC 0002#98
fengmk2 merged 1 commit into
mainfrom
rfc-0002-fork-only-gate

Conversation

@fengmk2

@fengmk2 fengmk2 commented Aug 12, 2026

Copy link
Copy Markdown
Member

The vite-plus implementation runs the publish job in a GitHub environment, a control RFC 0002 never described. voidzero-dev/vite-plus#2404 narrowed that gate to fork PRs: preview-build-release (required reviewers) for forks, preview-build-release-auto (no protection rules) for same-repo PRs, which publish unattended once labeled.

Changes:

  • section 7 sketch: environment: expression on the publish job, keyed on a new is-fork output from authorize
  • section 7 details: new bullet on the two environments, the implicit-creation trap, why #2404 narrowed the gate, and the SR-1 re-assertion after any approval wait
  • section 8.1: the fork gate is the one control standing if authorize regresses; same-repo PRs skip it because the label binds consent to the exact built sha
  • section 8.4: the triage-permission risk now notes that a labeled same-repo PR publishes unattended

The vite-plus implementation runs the publish job in a GitHub
environment, a control the RFC never described. vite-plus#2404 narrowed
that gate to fork PRs: preview-build-release (required reviewers) for
forks, preview-build-release-auto (no protection rules) for same-repo
PRs, which publish unattended once labeled.

Record the gate in the section 7 workflow sketch and details, explain
its fork-only scope in 8.1, and note the unattended same-repo publish
in the 8.4 triage-permission risk.
@fengmk2
fengmk2 merged commit 75f47e1 into main Aug 13, 2026
4 checks passed
@fengmk2
fengmk2 deleted the rfc-0002-fork-only-gate branch August 13, 2026 01:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant