Round-2 cross-review (REQUEST CHANGES) folded: - B1 deploy-before-merge made a concrete CI-enforced gate (required status check fed by a box-exercised dispatch dry-run), not prose. - B2 added rollback for a prematurely-flipped privileged job that actually RAN (token rotate, revert opened PR/branch, audit the window) — distinct from an accidental merge. - B3 rollback is a tested, re-runnable script over ALL privileged surfaces (workflow, environment, App perms, branch protection), not a one-time manual run. - B4 Phase 3 explicitly gated on Phase 2 being fully provisioned + verified. - B5 /sh-security-review + GPT-4.1 cross-review RE-RUN on the actual enabled workflow before the flip, not only the inert version. - B6 docs/memory updated incrementally at each privileged step; Phase 6 is the final reconciliation pass. Plus FIX/NIT/QUESTION: gate-weakening pattern review, check-name discovery test, memory update on denylist change, snapshot retention in Phase 0, draft-PR notification (Phase 4) + conservative-rollout controls (Phase 5) made concrete. GH_TOKEN->GITHUB_TOKEN gate marked done (box alias added). |
||
|---|---|---|
| .. | ||
| DEPLOY-AUDIT.md | ||
| OPERATOR-RUNBOOK.md | ||
| P1-DEMO-SCRIPT.md | ||
| P3-LIVE-FLIP-PLAN.md | ||
| PROVISIONING-RUNBOOK.md | ||