DashboardpublishPrioritize fail-closed, test-backed pub…

Prioritize fail-closed, test-backed publishing security

Category: preference
Confidence: 0.80
ID: 01a08b8b-f362-79d2-b01e-133ed3379505
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 0
Source session: 0NVYBK4OcVTfjEcUh
Created: 2026-09-10 13:39:59
Updated: 2026-09-10 13:39:59

Content

When reviewing or changing the publishing system, preserve and verify security invariants end to end. Bind approvals and CI-ready state to the exact live issue title, body, relevant labels, actors, and latest label-event IDs; reject stale, malformed, manually forged, self-approved, or changed requests. Revalidate immediately before publishing. Keep automated approval allowlisted and proof-backed, isolate manual dispatches from repository secrets, use protected environments, and pin actions and containers to immutable revisions. Preserve workflow ordering that records attestations before labels and removes/re-adds ci-ready to generate a fresh event. Add or inspect focused tests that assert exact failure behavior, API calls, outputs, token separation, and step ordering.

Move to: