diff --git a/.github/workflows/workflow.yml b/.github/workflows/workflow.yml index 997e6ea..fac2966 100644 --- a/.github/workflows/workflow.yml +++ b/.github/workflows/workflow.yml @@ -53,6 +53,16 @@ on: required: false type: string default: "" + allow-fork: + description: | + The `owner/repo` name of a fork that is allowed to publish to FlakeHub. + Publishing from a fork is skipped unless `github.repository` matches this value exactly. + Forks of the named repository still skip publishing. + + Example: `DeterminateSystems/nix-eval-jobs` + required: false + type: string + default: "" outputs: flake_name: value: ${{ jobs.success.outputs.flake_name }} @@ -171,15 +181,15 @@ jobs: contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 - if: ${{ !github.event.repository.fork && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} + if: ${{ (!github.event.repository.fork || (inputs.allow-fork != '' && github.repository == inputs.allow-fork)) && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} with: persist-credentials: false - uses: DeterminateSystems/determinate-nix-action@main - if: ${{ !github.event.repository.fork && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} + if: ${{ (!github.event.repository.fork || (inputs.allow-fork != '' && github.repository == inputs.allow-fork)) && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} - uses: DeterminateSystems/flakehub-cache-action@main - if: ${{ !github.event.repository.fork && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} + if: ${{ (!github.event.repository.fork || (inputs.allow-fork != '' && github.repository == inputs.allow-fork)) && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} - uses: DeterminateSystems/flakehub-push@main - if: ${{ !github.event.repository.fork && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} + if: ${{ (!github.event.repository.fork || (inputs.allow-fork != '' && github.repository == inputs.allow-fork)) && inputs.visibility != '' && (github.ref == format('refs/heads/{0}', inputs.default-branch) || startsWith(github.ref, 'refs/tags/')) }} id: publish with: rolling: ${{ github.ref == format('refs/heads/{0}', inputs.default-branch) }} diff --git a/README.md b/README.md index 04a2415..8a86016 100644 --- a/README.md +++ b/README.md @@ -60,6 +60,7 @@ You'll see something like this when your workflow has run successfully: | `fail-fast` | Whether to cancel all in-progress jobs if any matrix job fails | `true` | | `runner-map` | A custom mapping of [Nix system types][nix-system] to desired Actions runners | `{ "aarch64-darwin": "macos-latest", "x86_64-linux": "ubuntu-latest", "aarch64-linux": "ubuntu-latest" }` | | `extra-nix-conf` | Extra Nix configuration to pass to Determinate Nix | | +| `allow-fork` | The `owner/repo` name of a fork that is allowed to publish to FlakeHub. Forks skip publishing unless `github.repository` matches this value exactly. | | ## Example configurations