You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This PR introduces a mandatory allowedWorkflows field in the version-1 Patchlane config and enforces a workflow allowlist policy across sync, promotion, and doctor operations. A new workflow-policy.ts module validates that the composed workflow tree matches the allowlist, implicitly including Patchlane-generated workflows (sync-upstream.yml, promote-tested-sync.yml). The patchlane init command auto-populates the allowlist from the detected CI workflow filename, and comprehensive tests and migration documentation are included.
LoadingConfidence: 4/5 ◉◉◉◉○ Safe with minor fixes
The implementation is thorough with strong validation, backward-compatible handling when allowedWorkflows is undefined, and comprehensive test coverage. The migration guide is well-documented. Minor consideration: the enforcement could fail for users who haven't yet added allowedWorkflows to their config.
Blast Radius — 2 dependent repositories, 3 total references
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
allowedWorkflowsin version-1 Patchlane configurationpatchlane initpopulate the detected CI filename, with an explicit override availablesync-upstream.ymlandpromote-tested-sync.ymlworkflowsdocs/migrations.mdwithvNextand versioned sectionsThe package version remains unchanged; the planned 0.5.0 version bump will be handled separately with the other fixes for that release.
Testing
npm testnpm run format:checknpm run artifacts:checkCloses #48