Dashboard › publish › Always perform strict read-only securit…
01a08c4c-5d5e-77d0-bf63-2311212b9749When reviewing release or workflow changes, independently inspect the full integrated diff against origin/main, including all changed and untracked behavioral files, without editing, formatting, staging, generating, or otherwise mutating the tree. Trace approval, CI, publication, failure, cancellation, and cleanup paths end to end, emphasizing immutable request binding, trusted-code execution, identity separation, fail-closed transitions, fresh ci-ready events, exact approved revisions, injection resistance, and dependency-independent deauthorization. Examine adversarial tests and run only read-only probes. Support every audit area with current file:line evidence and classify it PASS, CONCERN, or MUST-FIX in the requested order. Never return empty output; if tooling prevents review, begin with BLOCKED and quote the exact error. End with exactly MERGE or DO-NOT-MERGE.