From d33e74a181cdf643f025258f393ab49e10067890 Mon Sep 17 00:00:00 2001 From: JornC Date: Tue, 21 Jul 2026 14:04:32 +0200 Subject: [PATCH 1/2] Only run code-push on the canonical repo The code-push workflow deploys a -SNAPSHOT to the internal Nexus, which needs the NEXUS_* secrets. Forks do not have those, so any fork push that matches the branch filter fails on the deploy step. Guard the job on the repository so it only runs on aerius/tools. --- .github/workflows/on-code-push.yml | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/on-code-push.yml b/.github/workflows/on-code-push.yml index 198ed3f..6bb8f65 100644 --- a/.github/workflows/on-code-push.yml +++ b/.github/workflows/on-code-push.yml @@ -8,6 +8,7 @@ on: jobs: job: + if: github.repository == 'aerius/tools' runs-on: ubuntu-latest steps: From 3fa4b39e90f16d2c7ac6c8a74018d32f7dca5a49 Mon Sep 17 00:00:00 2001 From: JornC Date: Wed, 26 Aug 2026 13:19:27 +0200 Subject: [PATCH 2/2] Apply the same guard to the other workflows The tag, pull_request and create-release workflows can run in a fork too. Same rule in every file, so it is not something to reason about per event. --- .github/workflows/create-release.yml | 1 + .github/workflows/on-new-tag.yml | 1 + .../workflows/on-pull_request-opened-synchronize-reopened.yml | 1 + 3 files changed, 3 insertions(+) diff --git a/.github/workflows/create-release.yml b/.github/workflows/create-release.yml index 2fb357b..db6de92 100644 --- a/.github/workflows/create-release.yml +++ b/.github/workflows/create-release.yml @@ -12,6 +12,7 @@ on: jobs: job: + if: github.repository == 'aerius/tools' runs-on: ubuntu-latest permissions: contents: write diff --git a/.github/workflows/on-new-tag.yml b/.github/workflows/on-new-tag.yml index 3ef6240..8a8cf86 100644 --- a/.github/workflows/on-new-tag.yml +++ b/.github/workflows/on-new-tag.yml @@ -7,6 +7,7 @@ on: jobs: job: + if: github.repository == 'aerius/tools' runs-on: ubuntu-latest steps: diff --git a/.github/workflows/on-pull_request-opened-synchronize-reopened.yml b/.github/workflows/on-pull_request-opened-synchronize-reopened.yml index 31d1c78..e6bee00 100644 --- a/.github/workflows/on-pull_request-opened-synchronize-reopened.yml +++ b/.github/workflows/on-pull_request-opened-synchronize-reopened.yml @@ -6,6 +6,7 @@ on: jobs: job: + if: github.repository == 'aerius/tools' runs-on: ubuntu-latest steps: