Problem:
Where: .github/workflows/test_and_deploy.yml, deploy job
What's wrong
if: |
(
github.event_name != 'pull_request' && (
github.ref_name == 'main' ||
github.event_name == 'workflow_dispatch'
)
)
The ref_name == 'main' check is only enforced for push events. For workflow_dispatch, the inner || makes the branch check irrelevant the condition is true no matter which branch the workflow is manually run on.
| trigger |
event_name |
ref_name |
condition |
push to main |
push |
main |
✅ deploy (intended) |
| push to other branch |
push |
other |
❌ no deploy (correct) |
| pull_request |
pull_request |
any |
❌ no deploy (correct) |
workflow_dispatch on main |
workflow_dispatch |
main |
✅ deploy (intended) |
| workflow_dispatch on any other branch |
workflow_dispatch |
other |
✅ deploy bug |
- Anyone with write access who runs this workflow manually from a non-
main branch (easy to do by accident the Actions "Run workflow" branch dropdown doesn't default to main) will overwrite the live public docs site (numfocus.github.io/infrastructure) with unmerged/unreviewed content, with no straightforward git-based recovery of the prior deployment.
How to verify
Trace the boolean expression by hand (see table above), or trigger workflow_dispatch on a scratch branch in a fork and observe the deploy job runs.
Problem:
Where:
.github/workflows/test_and_deploy.yml,deployjobWhat's wrong
The
ref_name == 'main'check is only enforced forpushevents. Forworkflow_dispatch, the inner||makes the branch check irrelevant the condition istrueno matter which branch the workflow is manually run on.mainmainmainbranch (easy to do by accident the Actions "Run workflow" branch dropdown doesn't default tomain) will overwrite the live public docs site (numfocus.github.io/infrastructure) with unmerged/unreviewed content, with no straightforward git-based recovery of the prior deployment.How to verify
Trace the boolean expression by hand (see table above), or trigger
workflow_dispatchon a scratch branch in a fork and observe thedeployjob runs.