Skip to content

tend check: configuration drift on max-sixty/worktrunk #3729

Description

@worktrunk-bot

tend check reports one failing check on this repo. Filed by the nightly sweep so the drift is tracked rather than re-diagnosed each night; the bullet below is the current FAIL line with a one-line reason.

  • credential-environments — the release and signing environments each hold credentials, have no required reviewers, and admit tags, and no active all-tags ruleset restricting tag creation/update to admins could be verified. A run the bot can cause could therefore reach those credentials. Fix: gate each environment with a required reviewer that is not the bot, or a deployment policy naming only verified refs (protected branches, or tags under an admin-only all-tags ruleset).

The two secret-placement failures previously tracked here (claude-auth and repo-secret-allowlist) now pass — see the comment below for the delta.

Passing checks for reference: branch-protection:main, bot-permission, environment (the tend environment admits only main), environment-deployments, secrets (TEND_BOT_TOKEN present), claude-auth (CLAUDE_CODE_OAUTH_TOKEN present), repo-secret-allowlist.

The remaining failure is a repository-settings change that needs admin access, so the bot can't apply it. Nightly runs will refresh this body while the failure set is unchanged, and close the issue once tend check passes.

Last refreshed: 2026-08-10

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions