Skip to content

[codex] Harden CI publish checks#3

Merged
RedBeret merged 1 commit into
mainfrom
codex/ci-publish-check-hardening
Apr 29, 2026
Merged

[codex] Harden CI publish checks#3
RedBeret merged 1 commit into
mainfrom
codex/ci-publish-check-hardening

Conversation

@RedBeret
Copy link
Copy Markdown
Owner

Summary

  • run the full public-release check in the required Smoke Test workflow
  • reduce default workflow token permissions to read-only
  • use full checkout history so the publish gate can scan commit history in CI
  • disable persisted checkout credentials

Validation

  • bash scripts/publish-check.sh

@RedBeret RedBeret merged commit 282e335 into main Apr 29, 2026
3 checks passed
@RedBeret RedBeret deleted the codex/ci-publish-check-hardening branch April 29, 2026 02:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant