Skip to content

Observe release authentication and registry collisions without publishing - #700

Merged
EHotwagner merged 1 commit into
mainfrom
routine/game-release-admission-20261004
Oct 4, 2026
Merged

EHotwagner merged 1 commit into
mainfrom
routine/game-release-admission-20261004

Conversation

@EHotwagner

Copy link
Copy Markdown
Contributor

The existing Game release workflow could only test NuGet login after its first registry publication. Add a manual admission_only mode that excludes verification/publishing jobs and records bounded registry collision/authentication and OIDC/existing-package authority observations without pack or package publication. It uses the same repository-token permissions, pinned NuGet login and account selection as the publisher, strips credentials on cross-host redirects, and retains sanitized reports.

NuGet does not expose policy scopes in its exchange response, and missing-package verification returns404 before checking creation scope. The adapter creation scope therefore remains explicitly unproven even on successful observation. This change adds no owner-policy-export or manual-approval prerequisite and does not alter stable publication ordering, immutable custody or retained-byte recovery.

Validated offline: seven response/isolation/credential controls, existing successor source gate and release mutation controls, and git diff whitespace checks. No provider login, workflow dispatch, package/tag mutation or CLR execution occurred. PyYAML is unavailable locally, so a supplemental parser attempt could not run; native workflow qualification remains authoritative.

@EHotwagner
EHotwagner merged commit 8cd158d into main Oct 4, 2026
33 checks passed
@EHotwagner
EHotwagner deleted the routine/game-release-admission-20261004 branch October 9, 2026 16:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant