Skip to content

tend check: configuration drift on diffplug/dormouse #1069

Description

@dormouse-bot

tend check (tend 0.3.10, the pinned version) reports two FAILs on diffplug/dormouse. actions-event-policy is SKIP because the bot's token cannot read the Actions policies. Every other check passes.

  • tag-protection (FAIL): tend reports that the bot can create or repoint a tag and suggests tend check --fix to create an admin-gated all-tags ruleset.
  • credential-environments (FAIL): tend reports that blyg-publish, release-attest, and security-audit have no required reviewers and admit tags, with no all-tags ruleset restricting tags to admins that it could verify. It also reports that hosted-release-tag has no required reviewers and is reached by workflow_dispatch, so tend does not count its ref list as a gate.

These look like the check misreading this repository's layout, not real exposure. Tag protection is split across three rulesets, as docs/specs/security-ci.md requires. Tag operations covers ~ALL except refs/tags/hosted/** and blocks creation and update. Hosted tag creation and Hosted tag history cover refs/tags/hosted/**. The API reports current_user_can_bypass: never for the bot on all three. tend looks for a single all-tags ruleset, so it does not recognize the split. For hosted-release-tag, the only job using it (tag in .github/workflows/hosted-production.yml) needs: deploy, and deploy runs in hosted-production, which requires review from Ned or Edgar. A bot-fired dispatch therefore stops before the tag job. tend does not follow that needs chain.

Running tend check --fix as suggested would add an all-tags ruleset that also covers hosted/**. Unless the dormouse-hosted-tagger App were added as a bypass actor, that ruleset would block the App's tag creation. Adding the bypass would in turn break the security-ci.md rule that the App bypasses only Hosted tag creation. Two other ways to clear the FAILs: a tend change that unions tag rulesets and follows needs, or a required reviewer on hosted-release-tag, which the spec currently says requires no review. Filing upstream at max-sixty/tend needs a maintainer's go-ahead.

Last refreshed: 2026-10-10

Activity

  1. dormouse-bot commented on Oct 8, 2026

    @dormouse-bot
    CollaboratorAuthor

    Both FAILs trace to yesterday's intended change to how Hosted tags are minted, not to drift. eb1129e moved Hosted tagging to the dormouse-hosted-tagger App, and the rulesets were reshaped to match: Hosted tag creation and Hosted tag history were created, and Tag operations was updated to exclude refs/tags/hosted/**. All three changes landed between 2026-10-07T20:28:32Z and 20:28:45Z. Once that exclusion landed, no single ruleset covered every tag. That is the shape tend's tag-protection looks for, and credential-environments fails because it builds on that check for the v*-admitting environments.

    I checked the body's claims against the live repo and they hold:

    • Tag operations covers ~ALL except hosted/** and blocks creation and update. The two Hosted rulesets cover hosted/** with creation, and with update and deletion. The bot gets current_user_can_bypass: never on all three.
    • That split is what security-ci.md requires ("Tag operations must target ~ALL tags except refs/tags/hosted/**").
    • tag in .github/workflows/hosted-production.yml is the only job that uses hosted-release-tag, and it needs: deploy, which runs in the review-gated hosted-production environment. The spec also says hosted-release-tag requires no review.

    Nothing in this repo clears the check without weakening a rule that security-ci.md audits. The workable route is a tend change that combines tag rulesets and follows needs into a gated environment. Filing it needs a maintainer's go-ahead at max-sixty/tend. Until then, these two FAILs are expected on every sweep.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions