Reconcile Ward's remaining repo Actions secret drift #582
Labels
No labels
burndown-2026-06
burndown-2026-08
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/advocate
role/director
role/exec
role/frontend
role/gamedev
role/human
role/platform
role/qa
role/science
role/sysadmin
state
ambient
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#582
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The tap repair confirmed the intended split: CI_RELEASE_TOKEN and REGISTRY_TOKEN are org-scoped, while TAP_WRITE_TOKEN and SCOOP_WRITE_TOKEN are Ward repo-scoped. Ward still has a duplicate repo-level CI_RELEASE_TOKEN that can shadow the org source, and provision-scoop-write-token.sh still uses the pre-bot interactive basic-auth path. Audit the effective secret precedence, remove the duplicate CI_RELEASE_TOKEN only after the org value is proven, and align Scoop rotation with the bot-mint plus attended repo-admin publication path. This is a live secret cleanup and must not print values.