Skip to content

ci: keep publish dry runs independent of registry secrets - #66

Merged
lovasoa merged 1 commit into
mainfrom
codex/publish-dry-run-no-token
Sep 27, 2026
Merged

lovasoa merged 1 commit into
mainfrom
codex/publish-dry-run-no-token

Conversation

@lovasoa

@lovasoa lovasoa commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Fork and Dependabot PRs do not receive CRATES_TOKEN, so the current --token ${{ secrets.CRATES_TOKEN }} expands into a bare --token and Cargo exits before verifying packages.

Separate the secret-free dry-run step from actual publishing on version tags. Pass the registry token through CARGO_REGISTRY_TOKEN only in the publishing step, and explicitly give the workflow read-only repository permissions. Manual runs on version tags retain the existing publish behavior; other manual runs remain dry runs.

Validation: reproduced the empty-token argument failure locally; verified a disposable workspace successfully runs the replacement dry-run command using a fresh Cargo home with no credentials (no upload occurred). YAML parsing and shell syntax checks passed. No release was published. This merges independently of the shared toolchain change in #63.

@lovasoa
lovasoa added this pull request to the merge queue Sep 27, 2026
Merged via the queue into main with commit 0dad86d Sep 27, 2026
13 of 15 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant