📝 Track the CI publish hardening task

Also restores the runner force-pull task that the new entry had replaced; it is
still open (CONTRIBUTING § CI runner image documents the stale-image failure).
This commit is contained in:
tmu committed 2026-09-15 09:05:41 +00:00
1 parent 9c472c88c2
commit 75f2185b32
1 file changed
+6
+6
View File
@@ -54,3 +54,9 @@ Maintenance:
✔ Guard the invariant in CI (`Assert the baked tool cache is present`) @done
☐ Enable force-pull for the runner so a changed act-ci image is never missed @low
→ the tag encodes only the Node version, so a Dockerfile change yields new content under an unchanged tag; with `forcePull=false` the runner keeps the old image (see CONTRIBUTING § CI runner image)
☐ Improve CI publish
☐ Check whether publish job is only run on tags, if not, guard it
☐ Gate only single steps
☐ Do not publish to npm, if NPM_TOKEN is not set (e.g. PRs from forks)
☐ Do not publish to Gitea, if GITEA_TOKEN is not set (e.g. PRs from forks)
☐ Otherwise run the steps