tend check (tend 0.3.10, the pinned version) reports two FAILs on diffplug/dormouse. actions-event-policy is SKIP because the bot's token cannot read the Actions policies. Every other check passes.
tag-protection (FAIL): tend reports that the bot can create or repoint a tag and suggests tend check --fix to create an admin-gated all-tags ruleset.
credential-environments (FAIL): tend reports that blyg-publish, release-attest, and security-audit have no required reviewers and admit tags, with no all-tags ruleset restricting tags to admins that it could verify. It also reports that hosted-release-tag has no required reviewers and is reached by workflow_dispatch, so tend does not count its ref list as a gate.
These look like the check misreading this repository's layout, not real exposure. Tag protection is split across three rulesets, as docs/specs/security-ci.md requires. Tag operations covers ~ALL except refs/tags/hosted/** and blocks creation and update. Hosted tag creation and Hosted tag history cover refs/tags/hosted/**. The API reports current_user_can_bypass: never for the bot on all three. tend looks for a single all-tags ruleset, so it does not recognize the split. For hosted-release-tag, the only job using it (tag in .github/workflows/hosted-production.yml) needs: deploy, and deploy runs in hosted-production, which requires review from Ned or Edgar. A bot-fired dispatch therefore stops before the tag job. tend does not follow that needs chain.
Running tend check --fix as suggested would add an all-tags ruleset that also covers hosted/**. Unless the dormouse-hosted-tagger App were added as a bypass actor, that ruleset would block the App's tag creation. Adding the bypass would in turn break the security-ci.md rule that the App bypasses only Hosted tag creation. Two other ways to clear the FAILs: a tend change that unions tag rulesets and follows needs, or a required reviewer on hosted-release-tag, which the spec currently says requires no review. Filing upstream at max-sixty/tend needs a maintainer's go-ahead.
Last refreshed: 2026-10-10
tend check(tend 0.3.10, the pinned version) reports two FAILs ondiffplug/dormouse.actions-event-policyis SKIP because the bot's token cannot read the Actions policies. Every other check passes.tag-protection(FAIL): tend reports that the bot can create or repoint a tag and suggeststend check --fixto create an admin-gated all-tags ruleset.credential-environments(FAIL): tend reports thatblyg-publish,release-attest, andsecurity-audithave no required reviewers and admit tags, with no all-tags ruleset restricting tags to admins that it could verify. It also reports thathosted-release-taghas no required reviewers and is reached byworkflow_dispatch, so tend does not count its ref list as a gate.These look like the check misreading this repository's layout, not real exposure. Tag protection is split across three rulesets, as
docs/specs/security-ci.mdrequires.Tag operationscovers~ALLexceptrefs/tags/hosted/**and blockscreationandupdate.Hosted tag creationandHosted tag historycoverrefs/tags/hosted/**. The API reportscurrent_user_can_bypass: neverfor the bot on all three. tend looks for a single all-tags ruleset, so it does not recognize the split. Forhosted-release-tag, the only job using it (tagin.github/workflows/hosted-production.yml)needs: deploy, anddeployruns inhosted-production, which requires review from Ned or Edgar. A bot-fired dispatch therefore stops before the tag job. tend does not follow thatneedschain.Running
tend check --fixas suggested would add an all-tags ruleset that also covershosted/**. Unless thedormouse-hosted-taggerApp were added as a bypass actor, that ruleset would block the App's tag creation. Adding the bypass would in turn break thesecurity-ci.mdrule that the App bypasses onlyHosted tag creation. Two other ways to clear the FAILs: a tend change that unions tag rulesets and followsneeds, or a required reviewer onhosted-release-tag, which the spec currently says requires no review. Filing upstream atmax-sixty/tendneeds a maintainer's go-ahead.Last refreshed: 2026-10-10