Skip to content

chore: share guarded CoinPay PR commands across repositories - #8

Merged
ralyodio merged 2 commits into
mainfrom
feat/guarded-pr-workflow
Sep 13, 2026
Merged

ralyodio merged 2 commits into
mainfrom
feat/guarded-pr-workflow

Conversation

@ralyodio

Copy link
Copy Markdown
Contributor

Adds a reusable pr-commands.yml workflow so repositories can install manual CoinPay PR commands with a small pinned caller. The shared job verifies the comment author's current write/maintain/admin permission, checks named credentials, runs an immutable action revision, and times out after five minutes. It never checks out PR code.

The caller example and setup docs distinguish explicit contributor-wallet payment requests from business-issued formal invoices. Formal invoice publishing remains disabled in the documented configuration; this change defines no automatic PR rate or payout.

Validation: typecheck, 215 existing action tests, 20 workflow authorization/setup tests, YAML parsing, and bundle rebuild with no dist changes. The exact pinned action bundle also passed mocked dry-run, explicit-wallet creation, and disabled formal-invoice cases with real sockets disabled; no live comments or financial resources were created.

@github-actions

Copy link
Copy Markdown

ThreatCrush Security Scan

0 finding(s)

No findings.

@ralyodio
ralyodio merged commit b315d62 into main Sep 13, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant