Skip to content

Add workflow_run handoff gates#2214

Open
Dolpme wants to merge 1 commit into
UnitOneAI:mainfrom
Dolpme:improve/pipeline-workflow-run-handoffs
Open

Add workflow_run handoff gates#2214
Dolpme wants to merge 1 commit into
UnitOneAI:mainfrom
Dolpme:improve/pipeline-workflow-run-handoffs

Conversation

@Dolpme

@Dolpme Dolpme commented Jun 9, 2026

Copy link
Copy Markdown

Addresses #2062.

Summary

  • Adds privileged workflow_run artifact handoff gates to the pipeline-security skill.
  • Requires producer/consumer workflow mapping, trusted source checks, artifact identity and integrity evidence, and cache isolation across trust boundaries.
  • Updates artifact integrity guidance, the report template, and the skill changelog.

Validation

  • git diff --check
  • Frontmatter required-field check across skills/ and roles/
  • index.yaml referenced-file existence check
  • Markdown fence-balance check for skills/devsecops/pipeline-security/SKILL.md
  • Target marker check for workflow_run, producer/consumer mapping, artifact identity, trust gate, cache isolation, privileged handoff reporting, and version 1.0.1
  • Prompt-injection workflow-equivalent pattern check

Bounty note: this is intended as an improver-tier contribution under CONTRIBUTING.md; payment details can be provided privately after maintainer acceptance.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant