Skip to content

Declare crates.io publishing Environment; keep live approval verification pending - #67

Draft
fruwe wants to merge 1 commit into
mainfrom
fruwe/crates-publishing-environment-v030
Draft

fruwe wants to merge 1 commit into
mainfrom
fruwe/crates-publishing-environment-v030

Conversation

@fruwe

@fruwe fruwe commented Oct 5, 2026

Copy link
Copy Markdown
Member

The crates publishing job currently has no GitHub Environment boundary. Declare environment: crates-io on that job while retaining the exact tag/dispatch triggers, actions, permissions and publish commands.

Checkpoint 4ade6d1e43503ae9cff95e4b9a70235caf35f672: YAML1.2 comparison verifies that this is the only parsed workflow change; ordinary push and remote head verified. No workflow invoked, no tag/publish.

Keep draft. This field alone does not prove a manual gate: live required reviewers/self-review restrictions/allowed tag rules and the matching crates.io Trusted Publisher repository/workflow/environment binding must be verified before ready/merge or publication. Connector Environment endpoints and prepared Cloud api.github.com are blocked. Independent exact-head review and required CI remain pending. Unreleased0.3.0 unchanged.

Refs #66; fruwehq/determa-state-docs#32.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant