Pin Comfy-Org/publish-node-action to commit 0eb6cd742945443bee7f79eeddd4f732780029a1 (the v1 head) so a moved tag cannot inject code. NOTE: the 1.0.1 release tag is broken (runs the removed 'comfy --yes' flag); this commit uses 'comfy --skip-prompt' and works.
27 lines
750 B
YAML
27 lines
750 B
YAML
name: Publish to Comfy registry
|
|
on:
|
|
workflow_dispatch:
|
|
push:
|
|
branches:
|
|
- main
|
|
- master
|
|
paths:
|
|
- "pyproject.toml"
|
|
|
|
permissions:
|
|
issues: write
|
|
|
|
jobs:
|
|
publish-node:
|
|
name: Publish Custom Node to registry
|
|
runs-on: ubuntu-latest
|
|
if: ${{ github.repository_owner == 'bradsec' }}
|
|
steps:
|
|
- name: Check out code
|
|
uses: actions/checkout@v4
|
|
- name: Publish Custom Node
|
|
uses: Comfy-Org/publish-node-action@0eb6cd742945443bee7f79eeddd4f732780029a1 # v1 (1.0.1 tag broken: removed comfy --yes flag)
|
|
with:
|
|
## Add your own personal access token to your Github Repository secrets and reference it here.
|
|
personal_access_token: ${{ secrets.REGISTRY_ACCESS_TOKEN }}
|