From bc42a44a48932226258f946b4c3fbc19bb30a869 Mon Sep 17 00:00:00 2001 From: Radoslaw Nowacki Date: Tue, 22 Sep 2026 13:08:57 +0200 Subject: [PATCH] fix(ci): publish OTA updates when a labelled pull request merges The job selected on `github.event.pull_request.labels` but triggered on `push`, where there is no pull request to read labels from. The condition was never true, so the job has skipped all 69 times it has been queued since January. Trigger on a pull request closing against main instead, so the label is readable, and check that it was merged rather than just closed. `pull_request_target` rather than `pull_request` because a fork's pull request cannot read secrets, and most contributions here come from forks. Only main is ever checked out, and the token is pinned to read, so no pull request author's code runs with it. Co-Authored-By: Claude Opus 5 (1M context) --- .github/workflows/updates.yml | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/.github/workflows/updates.yml b/.github/workflows/updates.yml index 336a01184e..07c4cab764 100644 --- a/.github/workflows/updates.yml +++ b/.github/workflows/updates.yml @@ -1,16 +1,26 @@ name: Expo EAS Updates + on: - push: + pull_request_target: + types: [closed] branches: - main + +permissions: + contents: read + jobs: publish: - if: ${{ (contains(github.event.pull_request.labels.*.name, 'example app')) }} + if: >- + ${{ github.event.pull_request.merged + && contains(github.event.pull_request.labels.*.name, 'example app') }} name: Install and publish runs-on: ubuntu-latest steps: - name: Checkout uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + with: + ref: main - name: Setup uses: ./.github/actions/setup