From 9c13ddf2d2a3c3b08f491946102bb6b74ea80116 Mon Sep 17 00:00:00 2001 From: Matt Peake Date: Tue, 8 Sep 2026 10:22:36 -0400 Subject: [PATCH] ci: route example dependency installs through Socket Firewall Add the WorkOS Socket Firewall setup action to the build job before pnpm is installed so npm-compatible dependency downloads are routed through the firewall. Public-repo contract: PUBLIC_SOCKET_FIREWALL_TOKEN, external-fork fallback (action-gated to genuine public fork PRs), checkout without persisted credentials. No publish/deploy in this job, so no teardown. --- .github/workflows/build-examples.yml | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/.github/workflows/build-examples.yml b/.github/workflows/build-examples.yml index db8036f..8650595 100644 --- a/.github/workflows/build-examples.yml +++ b/.github/workflows/build-examples.yml @@ -57,6 +57,14 @@ jobs: steps: - name: Checkout uses: actions/checkout@v4 + with: + persist-credentials: false + + - name: Setup Socket Firewall + uses: workos/setup-socket-firewall@ca93dd8aa351f54f4729fe3377a9be23c631c25d + with: + token: ${{ secrets.PUBLIC_SOCKET_FIREWALL_TOKEN }} + allow-external-fork-fallback: true - name: Install pnpm uses: pnpm/action-setup@v4