Skip to content

Design a private community-adoption audit channel for private repositories #11

Description

@cervantesh

Proposal

Extend the public adoption audit with a separately approved token and private reporting destination so private repository names and policy gaps never appear in public workflow logs or artifacts.

Acceptance criteria

  • Token scope and storage are documented and least-privilege.
  • Private repository results are emitted only to a private destination.
  • Public workflow output contains aggregate counts only.
  • Redaction and access-control tests cover failure paths.

Deferred: Outside frozen run scope and requires a private reporting destination

This proposal was discovered during the frozen public-issue run and is intentionally excluded from implementation in that run.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    proposalFuture work discovered during implementation; excluded from the current run.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions