Repository navigation
revert(ci): restore auto-deploy for the LNbits droplet - #261
Merged
Merged
Conversation
#260 changed this workflow to workflow_dispatch-only under a "production" environment, to satisfy audit finding N-020 (SSH deploy without an approval gate). That removed continuous deployment, which is behaviour the maintainer relies on. Reverted at their request. Continuous deployment here is a deliberate trade-off and it is the maintainer's to make, not the audit's. The workflow comment records that, and records how to put the gate back in two lines if that ever changes. What is NOT reverted, because it was a separate finding and was not asked for: P-018 — ENV_FILE and DIRECT_SSH_KEY still read from `secrets` only. They used to fall back to `vars.*`, and GitHub Actions variables are plaintext, readable by anyone with repo access, and NOT masked in job logs; an SSH private key supplied that way would be printed in the clear. Action pinning — actions/checkout stays pinned to its commit SHA. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
ThreatCrush Security Scan327 finding(s) HIGH/CRITICAL: 35 | MEDIUM: 38 | LOW: 254
…and 277 more. Full results in the Security tab. Snippets are redacted; ThreatCrush never prints matched credential material. |
ralyodio
added a commit
that referenced
this pull request
Aug 19, 2026
#260 changed this workflow to workflow_dispatch-only under a "production" environment, to satisfy audit finding N-020 (SSH deploy without an approval gate). That removed continuous deployment, which is behaviour the maintainer relies on. Reverted at their request. Continuous deployment here is a deliberate trade-off and it is the maintainer's to make, not the audit's. The workflow comment records that, and records how to put the gate back in two lines if that ever changes. What is NOT reverted, because it was a separate finding and was not asked for: P-018 — ENV_FILE and DIRECT_SSH_KEY still read from `secrets` only. They used to fall back to `vars.*`, and GitHub Actions variables are plaintext, readable by anyone with repo access, and NOT masked in job logs; an SSH private key supplied that way would be printed in the clear. Action pinning — actions/checkout stays pinned to its commit SHA. Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Restores continuous deployment on push to master, reverting the approval gate #260 added for audit finding N-020.
Continuous deployment here is a deliberate trade-off and it's yours to make, not the audit's. The workflow comment records that, and records how to put the gate back in two lines if you ever want it.
Not reverted (separate findings, not asked for):
ENV_FILEandDIRECT_SSH_KEYstill read fromsecretsonly. They used to fall back tovars.*, and Actions variables are plaintext, readable by anyone with repo access, and not masked in job logs — an SSH private key supplied that way would be printed in the clear.actions/checkoutstays pinned to its commit SHA.Verified: only the trigger and the
environment:key changed; zero livevars.*references remain.🤖 Generated with Claude Code