DashboardpublishPrioritize strict security invariants i…

Prioritize strict security invariants in workflow changes

Category: preference
Confidence: 1.00
ID: 01a08872-b34b-7abc-b776-fd934cac0ebd
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 0
Source session: 15DLBkeeMQ5MaUxaS
Created: 2026-09-09 09:08:53
Updated: 2026-09-09 23:13:33

Content

Treat GitHub Actions and approval-flow changes as security-sensitive: preserve manual recovery, trusted-code execution, immutable transitions, and live provenance checks before privileged actions. Never claim workflow or environment guards isolate organization-wide SENTRY_INTERNAL_APP_PRIVATE_KEY or SENTRY_RELEASE_BOT_PRIVATE_KEY. Record their existing exposure as a separate Security-led workstream; it is not a merge blocker unless the current change worsens it.

Move to: