Skip to content

tend check: configuration drift on max-sixty/cargo-affected #34

Description

@cargo-affected-bot

uvx tend@latest check reports one failing check on max-sixty/cargo-affected.

  • credential-environments — the release environment has no required reviewers and admits tags, and no active all-tags ruleset restricting tag creation and update to admins could be verified, so a run the bot can cause reaches that environment's credentials. Gate it with a required reviewer that is not the bot, or a deployment policy naming only verified refs (protected branches, or tags under an admin-only all-tags ruleset). This is a repo-settings change: Settings → Environments → release.
Full tend check output
  PASS  branch-protection:main — Branch 'main' is protected
  PASS  bot-permission — Bot 'cargo-affected-bot' has 'write' permission
  PASS  environment — Environment 'tend' admits only main
  PASS  environment-deployments — No job files a deployment for the 'tend' environment
  FAIL  credential-environments — A run the bot can cause reaches a credential: 'release' has no required reviewers, and admits tags, and no active all-tags ruleset restricting creation and update to admins could be verified. Gate each environment with a required reviewer that is not the bot, or a deployment policy naming only verified refs (protected branches, or tags under an admin-only all-tags ruleset); move an OIDC job into such an environment.
  PASS  secrets — Required secrets present: TEND_BOT_TOKEN
  PASS  claude-auth — Claude auth secret present: CLAUDE_CODE_OAUTH_TOKEN
  PASS  repo-secret-allowlist — All secrets available to workflows are in allowlist

See tend's security model.

Last refreshed: 2026-08-12

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions