Dashboard › publish › Always perform comprehensive evidence-b…
01a085a5-5856-7fba-acf4-c4f01b289cf4| Project | Hits | Last recalled |
|---|---|---|
| opencode-lore | 2 | 20h ago |
For changes to the publishing and GitHub Actions release flow, verify the exact repository state rather than relying on assumptions. Run focused regression tests for modified behavior, then the full Vitest suite, ESLint, and whitespace checks; report exact commands, test counts, failures, and whether issues are new or pre-existing. Inspect workflow triggers, permissions, secret boundaries, immutable action/image pinning, approval attestations, and fail-closed behavior. Preserve explicitly required recovery and event semantics, such as manual dispatch availability and always re-adding ci-ready. Treat substantive security-review findings as merge blockers, add regression coverage before fixing them, and obtain an independent final review when security-sensitive workflow logic changes.