Disable GitHub-side publishing across active repositories #676
Labels
No labels
burndown-2026-06
autonomy
async-consult
autonomy
epic
autonomy
headless
autonomy
live-collab
coherence-core
priority
P0
priority
P1
priority
P2
priority
P3
priority
P4
qa-fixture
role/ai
role/creator
role/design
role/director
role/engineer
role/exec
role/human
role/ops
role/qa
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
coilyco-flight-deck/infrastructure#676
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Goal: GitHub remains a downstream mirror and does not independently build, publish, deploy, create Releases, or mutate tags.
Done when:
Historical tag migration safety:
Non-goals:
Fleet verification complete. All 32 active GitHub repositories have Actions disabled, default workflow permissions set to read, and Actions PR approval disabled. A live scan found 11 current workflow files and zero tag, Release, package, image, Pages, or deployment publishers. Three workflows request contents: write only for Dependabot merge or website data refresh, and all are inert behind the repository-wide Actions fence. cli-guard commit e76edeb5352bf0aad4d4b95ed93602056a461a7f removed the only current publisher from Forgejo and GitHub main. Actions must stay disabled until the historical tag import completes, then non-publishing validation may return.