From 1794f03fb95b64e04e398e4899403c152d3af0d9 Mon Sep 17 00:00:00 2001 From: Todd Baert Date: Wed, 16 Apr 2025 12:11:05 -0400 Subject: [PATCH 1/3] chore: add publish env Signed-off-by: Todd Baert --- .github/workflows/merge.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 72a3a3c32..14f7a89a8 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -16,6 +16,7 @@ permissions: jobs: build: + environment: publish runs-on: ubuntu-latest steps: From b89e28ef2bb0febf1fd253db5a704d9d83bb144c Mon Sep 17 00:00:00 2001 From: Todd Baert Date: Wed, 16 Apr 2025 12:12:07 -0400 Subject: [PATCH 2/3] Update release.yml Signed-off-by: Todd Baert --- .github/workflows/release.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index f5c1a2e74..7359285d0 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -12,6 +12,7 @@ permissions: # added using https://github.com/step-security/secure-workflows jobs: release-please: + environment: publish permissions: contents: write # for google-github-actions/release-please-action to create release commit pull-requests: write # for google-github-actions/release-please-action to create release PR From 8a38f0fdc0d888371e6c04ccf30640d8f358bc81 Mon Sep 17 00:00:00 2001 From: Todd Baert Date: Wed, 16 Apr 2025 12:13:02 -0400 Subject: [PATCH 3/3] Update merge.yml Signed-off-by: Todd Baert --- .github/workflows/merge.yml | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/.github/workflows/merge.yml b/.github/workflows/merge.yml index 14f7a89a8..edb3c6ef7 100644 --- a/.github/workflows/merge.yml +++ b/.github/workflows/merge.yml @@ -9,7 +9,8 @@ name: on-merge on: push: - branches: [ master, main ] + branches: + - main permissions: contents: read