Skip to content

workflows/main: re-enable read-only cachix for untrusted builds#398

Merged
MattSturgeon merged 1 commit into
NixOS:masterfrom
MattSturgeon:enable-cachix
May 21, 2026
Merged

workflows/main: re-enable read-only cachix for untrusted builds#398
MattSturgeon merged 1 commit into
NixOS:masterfrom
MattSturgeon:enable-cachix

Conversation

@MattSturgeon
Copy link
Copy Markdown
Contributor

@MattSturgeon MattSturgeon commented May 21, 2026

This partially reverts 903898a from #393.

Cachix is configured on all runs, but the authToken is only configured on push events to avoid exposing it to untrusted PR code.

cc @mdaniels5757

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 21, 2026

Nixpkgs diff

Comment thread .github/workflows/main.yml
@MattSturgeon MattSturgeon merged commit 54c4e79 into NixOS:master May 21, 2026
2 checks passed
@MattSturgeon MattSturgeon deleted the enable-cachix branch May 21, 2026 22:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants