ci: only build and push containers from the upstream repository - #1888
Merged
Merged
Conversation
Forks that carry the DOCKERHUB_* secrets run the same weekly schedule and push to the same Docker Hub repository. On 2026-09-13 the sbryngelson/MFC fork, four commits behind master, overwrote the nightly-* tags with stale images three hours after the upstream run had pushed fresh ones. Guard the Container job (and, through needs:, manifests) the same way the coverage and docs workflows already do.
Contributor
There was a problem hiding this comment.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Pull request overview
Adds a repository guard to prevent forks (even with Docker Hub secrets) from running the scheduled container build/push workflow and overwriting upstream Docker tags.
Changes:
- Gate the
Containerjob to run only whengithub.repositorymatches the upstream repo (MFlowCode/MFC).
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Forks that carry the
DOCKERHUB_*secrets run the same weeklyContainerizationschedule and push to the same Docker Hub repository. On 2026-09-13 thesbryngelson/MFCfork, four commits behind master, overwrote everynightly-*tag on Docker Hub with stale images three hours after the upstream run had pushed fresh ones. This adds thegithub.repository == 'MFlowCode/MFC'guard that the coverage and docs workflows already use;manifestsis skipped automatically throughneeds: Container.Context: https://github.com/MFlowCode/MFC/deployments/containers (the Sep 13 upstream run also lost its
manifestsjob to a GitHub internal error; that run has been re-run separately).Acknowledgement