Skip to content

Policy: Allow opted-in draft workflow pin refreshes - #96

Merged
JJJ merged 1 commit into
mainfrom
feature/managed-workflow-pin-preauthorization
Sep 21, 2026
Merged

JJJ merged 1 commit into
mainfrom
feature/managed-workflow-pin-preauthorization

Conversation

@JJJ

@JJJ JJJ commented Sep 21, 2026

Copy link
Copy Markdown
Contributor

This proposes a narrow standing authorization for preparing fleet-managed CI and release caller pin refreshes in repositories that explicitly opt in. The local diff must be limited to the existing reusable-workflow SHA pins, and the target central commit and old-to-new workflow behavior must be checked before pushing.

The proposal does not authorize marking a PR ready, merging it, or publishing a release. It also does not opt in any plugin repository or change the synchronizer. Those remain separate decisions. The organization validation suite passes.

@JJJ
JJJ marked this pull request as ready for review September 21, 2026 07:05
@JJJ
JJJ merged commit 055a76a into main Sep 21, 2026
1 check passed
@JJJ
JJJ deleted the feature/managed-workflow-pin-preauthorization branch September 21, 2026 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant