Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[SRE-2781] Set publishing workflows to use prod env #2481

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

dhf22
Copy link
Contributor

@dhf22 dhf22 commented Dec 20, 2024

TS_IMMUTABLE_SDK_NPM_TOKEN secret will now be stored as an environment secret in prod environment, meaning it will only be accessible from workflows running against prod env. This is to ensure only protected main brain with required reviews is able to publish to NPM to mitigate potential security incidents.

Prod env will require reviewers from the sdk team, and these workflows will only be executable against main.

@dhf22 dhf22 requested a review from a team as a code owner December 20, 2024 00:26
Copy link

nx-cloud bot commented Dec 20, 2024

View your CI Pipeline Execution ↗ for commit 1eb4593.

Command Status Duration Result
nx run-many --target=build --projects=@imtbl/sdk ✅ Succeeded 2s View ↗
nx affected -t build,lint,test,typecheck ✅ Succeeded <1s View ↗

☁️ Nx Cloud last updated this comment at 2024-12-20 00:28:41 UTC

@immutable-art
Copy link
Contributor

Relates to #2480

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

Successfully merging this pull request may close these issues.

2 participants