diff --git a/.github/workflows/on-pr.yml b/.github/workflows/on-pr.yml index 25bbaa2cc9..62a995d864 100644 --- a/.github/workflows/on-pr.yml +++ b/.github/workflows/on-pr.yml @@ -190,6 +190,12 @@ jobs: # matrix (i.e. not yet labeled "Ready to merge" or "Full CI build"). if: ${{ needs.should-run.outputs.go == 'true' && (github.event_name != 'pull_request' || contains(github.event.pull_request.labels.*.name, 'Ready to merge') || contains(github.event.pull_request.labels.*.name, 'Full CI build')) }} uses: ./.github/workflows/reusable-package.yml + with: + # A pull request builds packages to prove they still build, and publishes + # nothing. Stated rather than left to the input's default, so that changing + # that default cannot start publishing from pull requests. No secrets are + # passed either, which is the second reason a publish here cannot succeed. + publish: false upload-recipe: needs: diff --git a/.github/workflows/reusable-package.yml b/.github/workflows/reusable-package.yml index ddbb04c47c..700ec9180b 100644 --- a/.github/workflows/reusable-package.yml +++ b/.github/workflows/reusable-package.yml @@ -198,7 +198,10 @@ jobs: strategy: fail-fast: false matrix: ${{ fromJson(needs.generate-matrix.outputs.matrix) }} - name: "publish ${{ matrix.xrpld_artifact_name }}" + # The name says which of the two this is, because the job runs either way: + # with publish false it passes --dry-run and uploads nothing, and a job + # called "publish ..." succeeding on a pull request reads like a release. + name: "publish ${{ matrix.xrpld_artifact_name }}${{ !inputs.publish && ' (dry run)' || '' }}" permissions: contents: read runs-on: ["self-hosted", "Linux", "X64", "heavy"]