DashboardpublishAlways fail closed when release request…

Always fail closed when release requests or approvals change

Category: preference
Confidence: 0.80
ID: 01a08953-e617-73da-b501-a745cfe2b100
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 0
Source session: 15DLBkeeMQ5MaUxaS
Created: 2026-09-10 03:19:32
Updated: 2026-09-10 03:19:32

Content

Treat the canonical parsed publish request and its approval as immutable, event-bound security state. Use Publish’s shared title parser everywhere so CI and publishing resolve exactly the same target. Bind approval and CI-ready attestations to the live title, body, dry-run state, label actor, and label event. Revalidate after potentially mutable operations and immediately before adding ci-ready or publishing. If the issue is renamed, edited, re-approved, relabeled, or otherwise differs from the approved request, revoke accepted as appropriate and stop; never advance it to ci-ready. Automated approvals must use the trusted Internal App attestation path rather than direct bot labels. For manually dispatched workflows, check out trusted default-branch code before creating or exposing privileged credentials.

Move to: