DashboardcraftPrefer security-focused state isolation…

Prefer security-focused state isolation across release workflows

Category: preference
Confidence: 0.80
ID: 01a03998-b5b5-7567-94f7-36b9816d289b
Project ID: e16af391-c497-4837-b681-c849a5514499
Cross-project: No
Recalled in other projects: 0
Source session: 1bwAST7ENFvDRuqqJ
Created: 2026-08-25 15:45:04
Updated: 2026-08-25 15:45:04

Content

When implementing or reviewing publish-workspace changes, ensure state-file handling is secure, deterministic, and consistently propagated across Craft and acceptance actions. Isolate publish-resume state by repository/path/version and selected workspace, use collision-safe encoding for workspace identifiers, reject unsafe paths/traversal, and avoid repository-writable legacy state. Inspect and update all producer/consumer contracts together, including workflow inputs, issue-title parsing, and issue-update lookup. Add or maintain regression tests for scoped and unscoped behavior, filename compatibility, malformed inputs, and state restoration.

Move to: