DashboardpublishAlways treat release authorization work…

Always treat release authorization workflows as security-critical and fail closed

Category: preference
Confidence: 0.80
ID: 01a08c29-3eff-7bd4-b7b8-8c7ba6c10cd0
Project ID: ac098440-8723-4582-9021-39e07a608100
Cross-project: No
Recalled in other projects: 1
Source session: 1BpBuVO0t33JPd6VY
Created: 2026-09-09 16:01:09
Updated: 2026-09-10 16:31:48

Cross-Project Recalls

ProjectHitsLast recalled
opencode-lore 1 15h ago

Content

When reviewing publish or release-authorization changes, inspect the exact current working tree, related workflows, implementation modules, and tests. Pay special attention to race-resistant revalidation of live issue state, request digests, label events, requester/approver separation, trusted attestation authors, and identity handoffs before CI-ready or publishing transitions. Verify untrusted dispatches cannot access secrets or execute arbitrary refs, and confirm actions and container images are immutably pinned. Report only substantive, evidence-backed concerns with precise file and line references; do not speculate or edit files when a read-only review is requested.

Move to: