From 23b2c3d6afd3170920bc00435f5013b7464e2795 Mon Sep 17 00:00:00 2001 From: "Kai (Tam Nhu) Tran" <61256810+kaitranntt@users.noreply.github.com> Date: Tue, 30 Jun 2026 12:21:33 -0400 Subject: [PATCH] fix: restrict bar release workflow to main (#1612) --- .github/workflows/bar-release.yml | 6 +++++- docs/ccs-bar.md | 4 ++-- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/bar-release.yml b/.github/workflows/bar-release.yml index 9e2e2e09..78dc3b2a 100644 --- a/.github/workflows/bar-release.yml +++ b/.github/workflows/bar-release.yml @@ -5,7 +5,7 @@ name: Bar Release # # Scoped deliberately so it NEVER burdens other PRs or CI: # - Triggers ONLY on push to `main` that changes `macos-bar/**`, or a manual -# run. Regular PRs, dev pushes, and non-bar changes do not start it. +# run from `main`. Regular PRs, dev pushes, and non-bar changes do not start it. # - Runs ONLY on the dedicated self-hosted macOS runner (label `ccs-bar` on # kai-minim4). The Linux CI runners never match this job, and this job never # competes for them. @@ -32,10 +32,14 @@ concurrency: jobs: release: name: Build and publish CCS Bar + if: github.ref == 'refs/heads/main' runs-on: [self-hosted, macos, ccs-bar] steps: - name: Checkout uses: actions/checkout@v4 + with: + ref: main + persist-credentials: false - name: Read bar version id: ver diff --git a/docs/ccs-bar.md b/docs/ccs-bar.md index cc9e12b3..3226d6ec 100644 --- a/docs/ccs-bar.md +++ b/docs/ccs-bar.md @@ -126,10 +126,10 @@ The app ships as a single floating GitHub release asset, `CCS-Bar.app.zip` under The `Bar Release` workflow (`.github/workflows/bar-release.yml`) builds and publishes the asset automatically. It is scoped tightly so it never affects other PRs or CI: -- It runs only on a push to `main` that touches `macos-bar/**`, or a manual run from the Actions tab (`workflow_dispatch`). +- It runs only on a push to `main` that touches `macos-bar/**`, or a manual run from the Actions tab (`workflow_dispatch`) when the selected ref is `main`. - It runs only on the dedicated self-hosted macOS runner (label `ccs-bar`); the Linux CI runners never pick it up and it never competes for them. -So bar changes reach users when they land on `main` (the stable cadence). To cut a release without a code change, or to re-publish, trigger the workflow manually. +So bar changes reach users when they land on `main` (the stable cadence). To cut a release without a code change, or to re-publish, trigger the workflow manually with `main` selected as the workflow ref. ### Manual fallback