From d23f1db2e2df921b57e847d8269c54bc805b8718 Mon Sep 17 00:00:00 2001 From: dennisvang <29799340+dennisvang@users.noreply.github.com> Date: Thu, 10 Sep 2026 10:55:17 +0200 Subject: [PATCH 1/2] prevent docker-publish job from running in forks by checking repo-owner Checks for owner 'FAIRDataTeam' by default, but this can be overridden using an optional 'repo-owner' input. Also rename the 'build' job to a more apt 'publish' --- .github/workflows/docker-publish.yml | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/.github/workflows/docker-publish.yml b/.github/workflows/docker-publish.yml index 668fc9a..60852f1 100644 --- a/.github/workflows/docker-publish.yml +++ b/.github/workflows/docker-publish.yml @@ -44,10 +44,17 @@ on: required: false default: linux/amd64,linux/arm64 type: string + repo-owner: + description: 'The publish job only runs if repository owner matches this value, so it will not run on forks.' + required: false + default: 'FAIRDataTeam' + type: string jobs: - build: + publish: runs-on: ubuntu-latest + # https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#example-only-run-job-for-specific-repository + if: github.repository_owner == inputs.repo-owner steps: - # https://github.com/actions/checkout name: Clone git repo From e7c1cd2f6e3b8046755fbf6f396d9ead185f7186 Mon Sep 17 00:00:00 2001 From: dennisvang <29799340+dennisvang@users.noreply.github.com> Date: Thu, 10 Sep 2026 11:03:50 +0200 Subject: [PATCH 2/2] do not run maven-publish on forks can be overridden by setting the repo-owner input --- .github/workflows/maven-publish.yml | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/.github/workflows/maven-publish.yml b/.github/workflows/maven-publish.yml index b0fd712..c3fdbcc 100644 --- a/.github/workflows/maven-publish.yml +++ b/.github/workflows/maven-publish.yml @@ -31,10 +31,17 @@ on: default: '' required: false type: string + repo-owner: + description: 'The publish job only runs if repository owner matches this value, so it will not run on forks.' + required: false + default: 'FAIRDataTeam' + type: string jobs: publish: runs-on: ubuntu-latest + # https://docs.github.com/en/actions/reference/workflows-and-actions/workflow-syntax#example-only-run-job-for-specific-repository + if: github.repository_owner == inputs.repo-owner steps: # https://docs.github.com/en/actions/use-cases-and-examples/building-and-testing/building-and-testing-java-with-maven # https://github.com/actions/setup-java