From 75f2185b326b828e9a883f41307bccc6d7f733c8 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Thomas=20M=C3=BCller?= Date: Tue, 15 Sep 2026 09:05:41 +0000 Subject: [PATCH] :memo: Track the CI publish hardening task MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Also restores the runner force-pull task that the new entry had replaced; it is still open (CONTRIBUTING § CI runner image documents the stale-image failure). --- backlog.tasks | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/backlog.tasks b/backlog.tasks index b0e2ff0..cba9f7e 100644 --- a/backlog.tasks +++ b/backlog.tasks @@ -54,3 +54,9 @@ Maintenance: ✔ Guard the invariant in CI (`Assert the baked tool cache is present`) @done ☐ Enable force-pull for the runner so a changed act-ci image is never missed @low → the tag encodes only the Node version, so a Dockerfile change yields new content under an unchanged tag; with `forcePull=false` the runner keeps the old image (see CONTRIBUTING § CI runner image) +☐ Improve CI publish + ☐ Check whether publish job is only run on tags, if not, guard it + ☐ Gate only single steps + ☐ Do not publish to npm, if NPM_TOKEN is not set (e.g. PRs from forks) + ☐ Do not publish to Gitea, if GITEA_TOKEN is not set (e.g. PRs from forks) + ☐ Otherwise run the steps