Repository navigation
Observe release authentication and registry collisions without publishing - #700
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The existing Game release workflow could only test NuGet login after its first registry publication. Add a manual
admission_onlymode that excludes verification/publishing jobs and records bounded registry collision/authentication and OIDC/existing-package authority observations without pack or package publication. It uses the same repository-token permissions, pinned NuGet login and account selection as the publisher, strips credentials on cross-host redirects, and retains sanitized reports.NuGet does not expose policy scopes in its exchange response, and missing-package verification returns404 before checking creation scope. The adapter creation scope therefore remains explicitly unproven even on successful observation. This change adds no owner-policy-export or manual-approval prerequisite and does not alter stable publication ordering, immutable custody or retained-byte recovery.
Validated offline: seven response/isolation/credential controls, existing successor source gate and release mutation controls, and git diff whitespace checks. No provider login, workflow dispatch, package/tag mutation or CLR execution occurred. PyYAML is unavailable locally, so a supplemental parser attempt could not run; native workflow qualification remains authoritative.