From 60e416b0fe839f6fdbe64278ace7bf629a4bbaf7 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Tue, 15 Sep 2026 09:06:48 +0000 Subject: [PATCH] :memo: Check off the CI publish task The publish job was already tag-only; the coarse NPM_TOKEN assert is replaced by per-step env gates, so an unset secret now skips only its own step. --- backlog.tasks | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/backlog.tasks b/backlog.tasks index cba9f7e..b7cd0e3 100644 --- a/backlog.tasks +++ b/backlog.tasks @@ -54,9 +54,9 @@ Maintenance: ✔ Guard the invariant in CI (`Assert the baked tool cache is present`) @done ☐ Enable force-pull for the runner so a changed act-ci image is never missed @low → the tag encodes only the Node version, so a Dockerfile change yields new content under an unchanged tag; with `forcePull=false` the runner keeps the old image (see CONTRIBUTING § CI runner image) -☐ Improve CI publish - ☐ Check whether publish job is only run on tags, if not, guard it - ☐ Gate only single steps - ☐ Do not publish to npm, if NPM_TOKEN is not set (e.g. PRs from forks) - ☐ Do not publish to Gitea, if GITEA_TOKEN is not set (e.g. PRs from forks) - ☐ Otherwise run the steps +✔ Improve CI publish @done + ✔ Check whether publish job is only run on tags, if not, guard it @done + ✔ Gate only single steps @done + ✔ Do not publish to npm, if NPM_TOKEN is not set (e.g. PRs from forks) @done + ✔ Do not publish to Gitea, if GITEA_TOKEN is not set (e.g. PRs from forks) @done + ✔ Otherwise run the steps @done