fix(ci): persist-credentials:false on auto path + document matcher semantics - #6
Merged
Merged
Conversation
…cher semantics Follow-ups from PR #4's own automated review: - Add persist-credentials:false to claude-review.yml's checkout for consistency with the mention path (low risk on the trusted in-repo path, but keeps the invariant). - Document in the spec why find -exec is a bypass (single command word-list) while command substitution / chaining is NOT (the matcher parses those and requires each segment to be allowlisted). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Addresses the two follow-ups the automated review raised on PR #4 (workflow hardening):
persist-credentials: falsewas on the mention checkout but not the auto-review checkout. Added it there too. Low risk on the auto path (trusted in-repo PRs, short-lived token) but keeps the 'reviewed content must not reach tokens' invariant uniform. Safe — the checkout fetch already happened;git diff/log/showare local andgh pr commentusesGH_TOKEN.find -execbypassed the allowlist (execution smuggled inside a single command word-list) while command substitution / chaining does not (the matcher parses those and requires each segment to be allowlisted).