Skip to content

ci(docs-truth): activate full token entitlement guard - #73

Merged
peycheff-com merged 1 commit into
mainfrom
codex/docs-truth-token-guard-pin-20260729
Jul 29, 2026
Merged

ci(docs-truth): activate full token entitlement guard#73
peycheff-com merged 1 commit into
mainfrom
codex/docs-truth-token-guard-pin-20260729

Conversation

@peycheff-com

Copy link
Copy Markdown
Contributor

What

Repins the reusable Docs Truth workflow to Mindburn-Labs/.github@b9040b9d9585bf035dd5178d7a4dcadbe9e2666e (#55).

That revision validates MINDBURN_ORG_READ_TOKEN against the complete checkout read-set before any checkout:

  • the selected subject repository;
  • .github inventory;
  • private docs ledger; and
  • private dev-orchestration runner.

Why

The July fleet probe showed two distinct entitlement failures: private subjects failed at their own checkout, while public subjects reached the later private-ledger checkout before failing. The new preflight identifies the exact inaccessible repository and HTTP status instead of surfacing a misleading checkout error.

Validation

  • actionlint .github/workflows/docs-truth.yml
  • git diff --check
  • exact one-file diff
  • central reusable workflow checks: Docs Truth, deterministic gates, and local validation passed on .github#55

DCO signed off. Workflow-only pin update.

Signed-off-by: mindburnlabs <mindburnlabs@gmail.com>
@strix-security

Copy link
Copy Markdown

Strix is installed on this repository, but we couldn't run this PR security review because this workspace's trial has ended. Add a card to resume code reviews here.

@peycheff-com
peycheff-com merged commit ace1b72 into main Jul 29, 2026
4 of 6 checks passed
@peycheff-com
peycheff-com deleted the codex/docs-truth-token-guard-pin-20260729 branch July 29, 2026 13:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants