ci: validate resource dispatch identifiers - #81
Draft
Jeremy1844 wants to merge 2 commits into
Draft
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
DO NOT MERGE — private producer grammar/length and maintainer-owned no-content staging are unverified.
Root cause
The
repository_dispatchport_idcrossed directly into the object-store command boundary. A malformed producer value could change the intended command argument instead of being treated as one identifier.Confidence is high, not confirmed. The public consumer boundary is reproduced, but the private producer contract and an authorized staging run remain unavailable.
Change
[A-Za-z0-9_-]{1,64}This draft addresses only
ADV-2026-0055/RC-0055. It does not change TLS (#78), credential transport (#80), sender authorization, package provenance, import idempotency, or atomic promotion.Regression-first evidence
stage@9d237dd4fb37dd1fb936e3f9649020cc43a374c8b73ceaba5060c84900cc0bfe0277524e2c42fd1c— 0/3 introduced tests pass708a25713c9d46a63ff092651ff9f19f0807c06d— 3/3 passjs-yaml4.1.0 parses all eight workflows; three relevant decoded Bash scripts passbash -nThe local credential-step check is synthetic. It is not a claim that GitHub-hosted step skipping or secret non-resolution has been observed.
Open-PR composition
port-from-v2.ymlbut edit independent TLS/authentication hunks1947cadb5605d4abf0d1029f5b442ad99ab7efe1These remain separate root causes and separate pull requests.
Required before review or merge
Migration, recovery, and scope
There is no user-data, schema, content, package, lockfile, or artifact migration. A rejected event should leave the repository and object store untouched. Correct the producer value and retry only after confirming no earlier partial execution; idempotency remains a separate root.
If the path must be paused, disable the dispatch/import automation. Do not restore direct event-to-command interpolation as rollback.
No credential, private package/source, cloud configuration, user data, lesson, translation, image, audio, video, PDF, Ellen G. White material, or other rights-controlled content was read, changed, or uploaded.