Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Triggering release workflow #1899

Open
gabibguti opened this issue Nov 21, 2023 · 0 comments
Open

Triggering release workflow #1899

gabibguti opened this issue Nov 21, 2023 · 0 comments

Comments

@gabibguti
Copy link

gabibguti commented Nov 21, 2023

Thanks for stopping by to let us know something could be better!

PLEASE READ: If you have a support contract with Google, please create an issue in the support console instead of filing on GitHub. This will ensure a timely response.

Is your feature request related to a problem? Please describe.
The way auto-release workflow is triggered, seems like anyone that opens a pull request with release-please in the branch name would be able to trigger a release.

https://github.com/googleapis/google-http-java-client/blob/main/.github/workflows/auto-release.yaml#L22

Not sure if this is working as intended.

Describe the solution you'd like
I suggest we add a second layer of verification or "approval" to run the release workflow, such as:

Describe alternatives you've considered
None.

Additional context
I'm Gabriela and I work on behalf of Google and the OpenSSF suggesting supply-chain security changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant