Dashboard › publish › Always treat release authorization work…
01a08c29-3eff-7bd4-b7b8-8c7ba6c10cd0| Project | Hits | Last recalled |
|---|---|---|
| opencode-lore | 1 | 15h ago |
When reviewing publish or release-authorization changes, inspect the exact current working tree, related workflows, implementation modules, and tests. Pay special attention to race-resistant revalidation of live issue state, request digests, label events, requester/approver separation, trusted attestation authors, and identity handoffs before CI-ready or publishing transitions. Verify untrusted dispatches cannot access secrets or execute arbitrary refs, and confirm actions and container images are immutably pinned. Report only substantive, evidence-backed concerns with precise file and line references; do not speculate or edit files when a read-only review is requested.