From eb21ba583cd373feb10f4eff5f8e3f42be081eef Mon Sep 17 00:00:00 2001 From: Saoud Rizwan <7799382+saoudrizwan@users.noreply.github.com> Date: Wed, 15 Jul 2026 15:35:09 -0700 Subject: [PATCH] fix(ci): restrict nightly publishing to main (#12322) --- .../workflows/ext-vscode-publish-nightly.yml | 17 +++++++---------- apps/vscode-rollout/README.md | 7 ++++--- 2 files changed, 11 insertions(+), 13 deletions(-) diff --git a/.github/workflows/ext-vscode-publish-nightly.yml b/.github/workflows/ext-vscode-publish-nightly.yml index 82eaa6a4fe..8132ba5e0b 100644 --- a/.github/workflows/ext-vscode-publish-nightly.yml +++ b/.github/workflows/ext-vscode-publish-nightly.yml @@ -54,13 +54,11 @@ jobs: permissions: contents: write name: Publish Cline (Nightly) Combined Extension - # Branch allowlist: main (the cron + real publishes) plus any branch being - # rehearsed with dry-run. NOTE this `if` is advisory only — a dispatched - # branch runs its own copy of this file. The enforced gate is the - # PublishNightly environment's deployment-branch policy (repo settings), - # which must list the same branches. Publish/tag steps are additionally - # gated to main below. - if: github.repository == 'cline/cline' && (github.ref == 'refs/heads/main' || github.ref == 'refs/heads/saoudrizwan/extension-ab-loader') + # Defense in depth: only protected main may enter the publishing environment. + # This `if` is advisory because a dispatched branch runs its own copy of this + # file; the enforced gate is the PublishNightly environment's deployment-branch + # policy, which must also allow only main. + if: github.repository == 'cline/cline' && github.ref == 'refs/heads/main' runs-on: ubuntu-latest environment: PublishNightly @@ -247,9 +245,8 @@ jobs: path: staging/cline-nightly-${{ steps.version.outputs.version }}.vsix if-no-files-found: error - # Publish/tag only from main and never on a dry run. Step-level (not - # job-level) gating so the PR branch can be dispatched with dry-run to - # produce an installable artifact before the workflow lands on main. + # The job is main-only; step-level dry-run gating still permits a build-only + # rehearsal without publishing or tagging. - name: Publish to VS Code Marketplace and Open VSX if: github.ref == 'refs/heads/main' && inputs.dry-run != true working-directory: staging diff --git a/apps/vscode-rollout/README.md b/apps/vscode-rollout/README.md index c9411078ac..d1d43bd5d1 100644 --- a/apps/vscode-rollout/README.md +++ b/apps/vscode-rollout/README.md @@ -148,9 +148,10 @@ The loader derives the namespace from its own `packageJSON.name` at runtime manifest's name — no build flags involved. Nightly builds also show a status-bar indicator (`Cline: Next` / `Cline: Legacy`); stable builds never do. -Dispatching the nightly workflow with `dry-run` builds and uploads the -installable `.vsix` without publishing or tagging — use that (from any branch) -to verify changes before they reach the cron. +Dispatching the nightly workflow from `main` with `dry-run` builds and uploads +the installable `.vsix` without publishing or tagging. The publish job is +intentionally restricted to `main` by both the workflow and the +`PublishNightly` environment's deployment-branch policy. ### Telemetry events