DashboardpublishAlways require fail-closed, request-bou…

Always require fail-closed, request-bound release authorization

Category: preference
Confidence: 0.80
ID: 01a0865d-b218-7936-9dc1-940d53546ed8
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 0
Source session: 15DLBkeeMQ5MaUxaS
Created: 2026-09-08 11:19:46
Updated: 2026-09-09 13:31:22

Content

When changing publish approval flows, preserve strict separation between human and automated authorization. Human approvers must have live GitHub repository permission at write, maintain, or admin level and must not self-approve. Automated bot requests must never authorize through collaborator permissions or by trusting the Internal App label actor alone; require the exact parsed repository/release path in auto-approve-repos.txt and a trusted attestation bound to the live request. Revalidate the issue’s open state, title, requester, current accepted-label actor/event, and relevant attestations before producing authorization or publishing. Treat malformed, missing, stale, mismatched, or changed state as unauthorized and fail closed.

Move to: