Dashboardpublishapproval-authorizer GitHub roles

approval-authorizer GitHub roles

Category: architecture
Confidence: 1.00
ID: 01a043ee-6db5-7c89-adb7-b023a45b59cc
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 0
Source session: 0A2neX6Lse1iBFBA4
Created: 2026-08-27 15:29:39
Updated: 2026-08-27 15:54:54

Content

Chose live GitHub collaborator permission checks over private security-as-code because Publish is public and GitHub reflects effective target-repository access without exposing RBAC. Humans authorize only with write, maintain, or admin; triage never authorizes. getsantry[bot] must never fall through to collaborator lookup: it authorizes only when its exact parsed repository/release path is in auto-approve-repos.txt, because bot repository access does not prove the event followed an allowlisted auto-approval path.

Move to: