Skip to content

fix(cd): authorize contract outputs and trusted private runner callers - #22

Merged
rldyourmnd merged 1 commit into
mainfrom
fix/workflow-contract-authorization
Sep 12, 2026
Merged

rldyourmnd merged 1 commit into
mainfrom
fix/workflow-contract-authorization

Conversation

@rldyourmnd

Copy link
Copy Markdown
Contributor

Five contract authorization jobs compared the requested SHA with an output that did not yet exist, so reviewed commits were rejected before checkout. Some consumers also lacked the intended comparison because a structural test found the misplaced line in the authorization job.

Authorize reviewed main ancestry on the hosted job, then check out only its exact output. Compare that output in each consumer. Before scheduling any private CD runner, require a private caller and a push, dispatch or schedule on its default branch. Public/PR/tag/non-default-branch callers can still use hosted plan/evidence validation; they cannot schedule private runners.

Validation: executed the actual workflow shell blocks against isolated Git repositories. The regression failed in all five affected workflows before the fix. Reviewed commits pass; foreign commits, malformed OIDs and unsafe caller contexts fail before authorization output. All 15 module tests, complete source/registry/trust validation and actionlint pass. No deployments or runner changes were executed.

Signed-off-by: rldyourmnd <danil@nddev.it.com>
@rldyourmnd
rldyourmnd merged commit 0fcdad5 into main Sep 12, 2026
5 checks passed
@rldyourmnd
rldyourmnd deleted the fix/workflow-contract-authorization branch September 12, 2026 19:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant