Skip to content

Commit e6f2ef9

Browse files
committed
Keep BlueBuild PR checks unprivileged
1 parent 2c7aad3 commit e6f2ef9

1 file changed

Lines changed: 12 additions & 8 deletions

File tree

.github/workflows/build.yml

Lines changed: 12 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -122,6 +122,7 @@ jobs:
122122
with:
123123
recipe: ${{ matrix.recipe }}
124124
cosign_private_key: ${{ secrets.SIGNING_SECRET }}
125+
push: ${{ github.event_name != 'pull_request' }}
125126
registry_token: ${{ github.token }}
126127
pr_event_number: ${{ github.event.number }}
127128
maximize_build_space: true
@@ -133,6 +134,7 @@ jobs:
133134
with:
134135
recipe: ${{ matrix.recipe }}
135136
cosign_private_key: ${{ secrets.SIGNING_SECRET }}
137+
push: ${{ github.event_name != 'pull_request' }}
136138
registry_token: ${{ github.token }}
137139
pr_event_number: ${{ github.event.number }}
138140
maximize_build_space: true
@@ -177,14 +179,16 @@ jobs:
177179
else
178180
echo "digest=${DIGEST}" >> "$GITHUB_OUTPUT"
179181
echo "${DIGEST}" > IMAGE_DIGEST
180-
echo "## Image Digest" >> "$GITHUB_STEP_SUMMARY"
181-
echo "" >> "$GITHUB_STEP_SUMMARY"
182-
echo "Pinned install reference:" >> "$GITHUB_STEP_SUMMARY"
183-
echo '```' >> "$GITHUB_STEP_SUMMARY"
184-
echo "sudo bash secai-bootstrap.sh --digest ${DIGEST}" >> "$GITHUB_STEP_SUMMARY"
185-
echo '```' >> "$GITHUB_STEP_SUMMARY"
186-
echo "" >> "$GITHUB_STEP_SUMMARY"
187-
echo "Full image ref: \`${IMAGE_REF}@${DIGEST}\`" >> "$GITHUB_STEP_SUMMARY"
182+
{
183+
echo "## Image Digest"
184+
echo ""
185+
echo "Pinned install reference:"
186+
echo '```'
187+
echo "sudo bash secai-bootstrap.sh --digest ${DIGEST}"
188+
echo '```'
189+
echo ""
190+
echo "Full image ref: \`${IMAGE_REF}@${DIGEST}\`"
191+
} >> "$GITHUB_STEP_SUMMARY"
188192
fi
189193
190194
- name: Upload image digest artifact

0 commit comments

Comments
 (0)