PASS branch-protection:main — Branch 'main' is protected
PASS bot-permission — Bot 'cargo-affected-bot' has 'write' permission
PASS environment — Environment 'tend' admits only main
PASS environment-deployments — No job files a deployment for the 'tend' environment
FAIL credential-environments — A run the bot can cause reaches a credential: 'release' has no required reviewers, and admits tags, and no active all-tags ruleset restricting creation and update to admins could be verified. Gate each environment with a required reviewer that is not the bot, or a deployment policy naming only verified refs (protected branches, or tags under an admin-only all-tags ruleset); move an OIDC job into such an environment.
PASS secrets — Required secrets present: TEND_BOT_TOKEN
PASS claude-auth — Claude auth secret present: CLAUDE_CODE_OAUTH_TOKEN
PASS repo-secret-allowlist — All secrets available to workflows are in allowlist
uvx tend@latest checkreports one failing check onmax-sixty/cargo-affected.releaseenvironment has no required reviewers and admits tags, and no active all-tags ruleset restricting tag creation and update to admins could be verified, so a run the bot can cause reaches that environment's credentials. Gate it with a required reviewer that is not the bot, or a deployment policy naming only verified refs (protected branches, or tags under an admin-only all-tags ruleset). This is a repo-settings change: Settings → Environments → release.Full
tend checkoutputSee tend's security model.
Last refreshed: 2026-08-12