From ec2a03208613a40a9fd76f0aece02551ba7ad5ad Mon Sep 17 00:00:00 2001 From: Johannes Fleck Date: Thu, 8 Oct 2026 10:27:32 +0200 Subject: [PATCH 1/2] fix(gh): no registry pushes for dependabot builds --- .github/workflows/build.yaml | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index fd680860..3c18bb90 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -121,7 +121,9 @@ jobs: TARGETARCH=${{ matrix.runner.arch }} container-file: docker/Dockerfile + # Dependabot PRs have no access to repository secrets, so they build the image without publishing it. - name: Publish Container Image + if: github.event.pull_request.user.login != 'dependabot[bot]' uses: stackabletech/actions/publish-image@e8aed001d347bcf693e41b61f4098b0cb94b4ab6 # v0.18.0 with: image-registry-uri: oci.stackable.tech @@ -133,7 +135,7 @@ jobs: publish-index-manifest: name: Publish/Sign ${{ needs.build-container-image.outputs.image-version }} Index - if: (github.event_name != 'merge_group') && needs.detect-changes.outputs.detected == 'true' + if: (github.event_name != 'merge_group') && needs.detect-changes.outputs.detected == 'true' && github.event.pull_request.user.login != 'dependabot[bot]' needs: - detect-changes - build-container-image @@ -162,6 +164,7 @@ jobs: needs: - detect-changes - build-container-image + - publish-index-manifest permissions: contents: read id-token: write From daa5223ed8419b664fdfb98438dfb390d6682ec1 Mon Sep 17 00:00:00 2001 From: Johannes Fleck Date: Thu, 8 Oct 2026 11:18:14 +0200 Subject: [PATCH 2/2] fix: pr feedback --- .github/workflows/build.yaml | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/.github/workflows/build.yaml b/.github/workflows/build.yaml index 3c18bb90..8deb3847 100644 --- a/.github/workflows/build.yaml +++ b/.github/workflows/build.yaml @@ -216,14 +216,20 @@ jobs: if: always() needs: - openshift-preflight-check + - detect-changes + - build-container-image + - publish-index-manifest - publish-helm-chart runs-on: ubuntu-latest steps: - name: Check results + env: + NEEDS_RESULTS: ${{ toJSON(needs.*.result) }} run: | set -euo pipefail - if [[ "${{ needs.openshift-preflight-check.result }}" == "failure" || "${{ needs.publish-helm-chart.result }}" == "failure" ]]; then - echo "One or more required jobs failed" + echo "$NEEDS_RESULTS" + if jq -e 'any(. == "failure" or . == "cancelled")' <<<"$NEEDS_RESULTS" >/dev/null; then + echo "One or more required jobs failed or were cancelled" exit 1 fi echo "All required jobs passed or were skipped"