Beyond schema changes Beyond migrations

CI/CD pipeline verification

planned
Planned

Unpinned actions, permission escalations, injection through untrusted inputs — rules for the pipelines AI increasingly edits.

Pipelines are code that runs with the repository’s secrets, and models edit them freely. The rule-shaped dangers are well known: third-party actions pinned to a mutable tag, workflow permissions widened to write-all, untrusted inputs interpolated into a shell step, pull_request_target with a checkout of the head. A deterministic corpus over the workflow tree is planned.

Want this moved up the roadmap?

The roadmap bends toward what connected teams actually need — tell us.

Also in Beyond schema changes