Skip to content

Add allow-fork input to let one named fork publish - #51

Merged
grahamc merged 2 commits into
mainfrom
graham/allow-fork
Sep 27, 2026
Merged

grahamc merged 2 commits into
mainfrom
graham/allow-fork

Conversation

@grahamc

@grahamc grahamc commented Sep 27, 2026 •

Copy link
Copy Markdown
Member

c74b8bc fixed the fork guard on the publish steps.
Before that fix, the guard never blocked anything.
Now repositories that are GitHub forks skip publishing without an error, and the job still reports success.

DeterminateSystems/nix-eval-jobs is a fork of NixOS/nix-eval-jobs.
Its releases after v3.21.9 did not reach FlakeHub because of this.
For example, in run 32404936425 (v3.22.1) the checkout, Nix, cache and flakehub-push steps all show "skipped".

This PR adds an allow-fork input.
Set it to the owner/repo name of the fork that is allowed to publish.
Publishing happens only when github.repository matches that value exactly, so forks of that fork still skip publishing.
When allow-fork is empty, the behavior does not change.

actionlint, prettier and zizmor pass locally.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • New Features
    • Workflows can now be configured to allow a specifically named fork to publish to FlakeHub. Publishing remains subject to the existing visibility and default-branch-or-tag requirements; other forks continue to skip publishing.
  • Documentation
    • Added guidance for the allow-fork option, including the required owner/repo format and how it determines whether a fork can publish.

grahamc and others added 2 commits September 27, 2026 16:41
Forks such as DeterminateSystems/nix-eval-jobs skip publishing since c74b8bc fixed the fork guard.
The allow-fork input names the one repository that can publish even though it is a fork.
Forks of that repository still skip publishing.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Essentials

Run ID: 1a86679b-9996-481f-9388-24e653b3b8fb

📥 Commits

Reviewing files that changed from the base of the PR and between 5c2c382 and 5c79aad.

📒 Files selected for processing (2)
  • .github/workflows/workflow.yml
  • README.md

Included review availability: This review used your included allowance. 4 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

The workflow adds an optional allow-fork input. Publishing steps can run from a fork when its repository name exactly matches the input. Existing visibility and default-branch-or-tag conditions remain. The README documents the input.

Changes

Fork publishing

Layer / File(s) Summary
Add and document the fork allowlist input
.github/workflows/workflow.yml, README.md
The workflow adds the optional allow-fork input with an empty default. The README documents that a fork must match the configured repository name.
Apply fork publishing conditions
.github/workflows/workflow.yml
Publishing steps permit a fork only when allow-fork is nonempty and exactly matches github.repository. Visibility and default-branch-or-tag conditions remain.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Feature

Suggested reviewers: lucperkins

Merge Risk: ⚪ Minimal · up to 5c79a

The new fork path requires a nonempty repository-name match and retains the existing publishing gates; no merge-blocking regression is established.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly states the main change: adding an input that allows one named fork to publish.
Description check ✅ Passed The description explains the publishing change, its motivation, the exact repository-match behavior, and reported validation. It also reports that Prettier passes, which addresses the template’s forma…
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@grahamc
grahamc merged commit fb4321e into main Sep 27, 2026
6 checks passed
@grahamc
grahamc deleted the graham/allow-fork branch September 27, 2026 14:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants