diff --git a/.github/workflows/runner-full-stack-e2e.yml b/.github/workflows/runner-full-stack-e2e.yml index d183cf4320..5c144c5339 100644 --- a/.github/workflows/runner-full-stack-e2e.yml +++ b/.github/workflows/runner-full-stack-e2e.yml @@ -669,7 +669,7 @@ jobs: report: name: Merge and enforce campaign result - if: always() && needs.catalog.result == 'success' + if: always() && !cancelled() && needs.catalog.result == 'success' needs: [catalog, daytona_image, test] outputs: history_source_ready: ${{ steps.history_source_ready.outputs.ready }} diff --git a/tests/runner-e2e/workflow-security.test.ts b/tests/runner-e2e/workflow-security.test.ts index 4596f21be7..8359b70448 100644 --- a/tests/runner-e2e/workflow-security.test.ts +++ b/tests/runner-e2e/workflow-security.test.ts @@ -93,6 +93,9 @@ describe("public repository paid workflow security", () => { expect(fullStack).toContain( "cancel-in-progress: ${{ github.ref != format('refs/heads/{0}', github.event.repository.default_branch) }}", ); + expect(fullStack).toContain( + "if: always() && !cancelled() && needs.catalog.result == 'success'", + ); for (const [secret, condition] of Object.entries({ OPENAI_API_KEY: "matrix.credentialName == 'OPENAI_API_KEY'", ANTHROPIC_API_KEY: "matrix.credentialName == 'ANTHROPIC_API_KEY'",