Skip to content

Conversation

@quekshuy
Copy link

@quekshuy quekshuy commented Nov 4, 2025

What

This pull request introduces a new GitHub Actions workflow to help protect the .env file from accidental or unauthorized changes during development. The workflow automatically checks for changes to .env in pull requests and blocks them if detected.

Workflow automation:

  • Added .github/workflows/block-env-updates.yml to automatically fail pull requests that add, modify, or rename the .env file using a custom GitHub Actions script.

Why

For security reasons, we'd prefer if no one accidentally adds org keys to this public repo.

For efficiency reasons (of getting our proposed changes into the mainline), we didn't make this repo a private mirror and instead went with the public fork.

A required check is one of the best compromises (and we can expand it to ensure that no commit actually changes .env instead of just requiring it at a per-PR level).

@quekshuy quekshuy force-pushed the quekshuy/block-env-updates-workflow/1 branch from 1b48291 to e0bb3df Compare November 4, 2025 11:21
@quekshuy quekshuy requested review from a team, daryllxd, julianalmandos, nvdai2401 and strawhatduckk and removed request for a team November 4, 2025 11:23
@quekshuy quekshuy merged commit ca5f43f into master Nov 6, 2025
7 of 8 checks passed
@quekshuy quekshuy deleted the quekshuy/block-env-updates-workflow/1 branch November 6, 2025 06:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants