[{"data":1,"prerenderedAt":682},["ShallowReactive",2],{"navigation":3,"external-navigation":214,"docs:\u002Feos\u002Fharbourmaster\u002Fexplanation\u002Fshared-action-trust-boundary":443},[4,8,201],{"title":5,"path":6,"stem":7},"Documentation","\u002F","README",{"title":9,"path":10,"stem":11,"children":12},"EOS","\u002Feos","eos\u002FREADME",[13,44,121,181],{"title":14,"collapsed":15,"path":16,"stem":17,"children":18,"page":43},"Adrs",true,"\u002Feos\u002Fadrs","eos\u002Fadrs",[19,23,27,31,35,39],{"title":20,"path":21,"stem":22},"Use Turborepo for the EOS monorepo","\u002Feos\u002Fadrs\u002F0001-use-turborepo-for-eos","eos\u002Fadrs\u002F0001-use-turborepo-for-eos",{"title":24,"path":25,"stem":26},"Use Oxc for linting and formatting","\u002Feos\u002Fadrs\u002F0003-use-oxc-for-linting-and-formatting","eos\u002Fadrs\u002F0003-use-oxc-for-linting-and-formatting",{"title":28,"path":29,"stem":30},"Lint Markdown and validate links in CI","\u002Feos\u002Fadrs\u002F0004-lint-markdown-in-ci","eos\u002Fadrs\u002F0004-lint-markdown-in-ci",{"title":32,"path":33,"stem":34},"Use Lefthook for repository-managed Git hooks","\u002Feos\u002Fadrs\u002F0005-use-lefthook-for-repository-git-hooks","eos\u002Fadrs\u002F0005-use-lefthook-for-repository-git-hooks",{"title":36,"path":37,"stem":38},"Use Commitlint's conventional configuration","\u002Feos\u002Fadrs\u002F0006-use-commitlint-conventional-configuration","eos\u002Fadrs\u002F0006-use-commitlint-conventional-configuration",{"title":40,"path":41,"stem":42},"Use Nx for EOS task execution","\u002Feos\u002Fadrs\u002F0007-use-nx-for-eos","eos\u002Fadrs\u002F0007-use-nx-for-eos",false,{"title":45,"path":46,"stem":47,"children":48},"Harbourmaster","\u002Feos\u002Fharbourmaster","eos\u002Fharbourmaster\u002FREADME",[49,58,71,96],{"title":50,"path":51,"stem":52,"children":53,"page":43},"Decisions","\u002Feos\u002Fharbourmaster\u002Fdecisions","eos\u002Fharbourmaster\u002Fdecisions",[54],{"title":55,"path":56,"stem":57},"AI-50: GitHub auth and fork pull request policy","\u002Feos\u002Fharbourmaster\u002Fdecisions\u002Fai-50-auth-and-fork-policy","eos\u002Fharbourmaster\u002Fdecisions\u002Fai-50-auth-and-fork-policy",{"title":59,"path":60,"stem":61,"children":62,"page":43},"Explanation","\u002Feos\u002Fharbourmaster\u002Fexplanation","eos\u002Fharbourmaster\u002Fexplanation",[63,67],{"title":64,"path":65,"stem":66},"The Harbourmaster review pipeline","\u002Feos\u002Fharbourmaster\u002Fexplanation\u002Freview-pipeline","eos\u002Fharbourmaster\u002Fexplanation\u002Freview-pipeline",{"title":68,"path":69,"stem":70},"The Harbourmaster shared-action trust boundary","\u002Feos\u002Fharbourmaster\u002Fexplanation\u002Fshared-action-trust-boundary","eos\u002Fharbourmaster\u002Fexplanation\u002Fshared-action-trust-boundary",{"title":72,"path":73,"stem":74,"children":75,"page":43},"How To","\u002Feos\u002Fharbourmaster\u002Fhow-to","eos\u002Fharbourmaster\u002Fhow-to",[76,80,84,88,92],{"title":77,"path":78,"stem":79},"How to add Harbourmaster reviews to a repository","\u002Feos\u002Fharbourmaster\u002Fhow-to\u002Fadd-harbourmaster-to-a-repository","eos\u002Fharbourmaster\u002Fhow-to\u002Fadd-harbourmaster-to-a-repository",{"title":81,"path":82,"stem":83},"How to build a pilot dashboard","\u002Feos\u002Fharbourmaster\u002Fhow-to\u002Fbuild-pilot-dashboard","eos\u002Fharbourmaster\u002Fhow-to\u002Fbuild-pilot-dashboard",{"title":85,"path":86,"stem":87},"How to configure model routing","\u002Feos\u002Fharbourmaster\u002Fhow-to\u002Fconfigure-model-routing","eos\u002Fharbourmaster\u002Fhow-to\u002Fconfigure-model-routing",{"title":89,"path":90,"stem":91},"How to request a Harbourmaster review","\u002Feos\u002Fharbourmaster\u002Fhow-to\u002Frequest-a-review","eos\u002Fharbourmaster\u002Fhow-to\u002Frequest-a-review",{"title":93,"path":94,"stem":95},"How to diagnose a Harbourmaster review failure","\u002Feos\u002Fharbourmaster\u002Fhow-to\u002Ftroubleshoot-a-review","eos\u002Fharbourmaster\u002Fhow-to\u002Ftroubleshoot-a-review",{"title":97,"path":98,"stem":99,"children":100,"page":43},"Reference","\u002Feos\u002Fharbourmaster\u002Freference","eos\u002Fharbourmaster\u002Freference",[101,105,109,113,117],{"title":102,"path":103,"stem":104},"Harbourmaster command-line interface","\u002Feos\u002Fharbourmaster\u002Freference\u002Fcli","eos\u002Fharbourmaster\u002Freference\u002Fcli",{"title":106,"path":107,"stem":108},"Harbourmaster configuration","\u002Feos\u002Fharbourmaster\u002Freference\u002Fconfiguration","eos\u002Fharbourmaster\u002Freference\u002Fconfiguration",{"title":110,"path":111,"stem":112},"Harbourmaster GitHub Action","\u002Feos\u002Fharbourmaster\u002Freference\u002Fgithub-action","eos\u002Fharbourmaster\u002Freference\u002Fgithub-action",{"title":114,"path":115,"stem":116},"Harbourmaster review behavior","\u002Feos\u002Fharbourmaster\u002Freference\u002Freview-behavior","eos\u002Fharbourmaster\u002Freference\u002Freview-behavior",{"title":118,"path":119,"stem":120},"Harbourmaster telemetry","\u002Feos\u002Fharbourmaster\u002Freference\u002Ftelemetry","eos\u002Fharbourmaster\u002Freference\u002Ftelemetry",{"title":72,"path":122,"stem":123,"children":124,"page":43},"\u002Feos\u002Fhow-to","eos\u002Fhow-to",[125,129,133,137,141,145,149,153,157,161,165,169,173,177],{"title":126,"path":127,"stem":128},"How to add an external documentation source","\u002Feos\u002Fhow-to\u002Fadd-external-documentation-source","eos\u002Fhow-to\u002Fadd-external-documentation-source",{"title":130,"path":131,"stem":132},"How to connect SDLC integrations","\u002Feos\u002Fhow-to\u002Fconnect-sdlc-integrations","eos\u002Fhow-to\u002Fconnect-sdlc-integrations",{"title":134,"path":135,"stem":136},"How to consume the EOS plugin marketplace","\u002Feos\u002Fhow-to\u002Fconsume-eos-marketplace","eos\u002Fhow-to\u002Fconsume-eos-marketplace",{"title":138,"path":139,"stem":140},"How to create a spike ticket","\u002Feos\u002Fhow-to\u002Fcreate-spike-ticket","eos\u002Fhow-to\u002Fcreate-spike-ticket",{"title":142,"path":143,"stem":144},"How to finalise a repository change","\u002Feos\u002Fhow-to\u002Ffinalise-change","eos\u002Fhow-to\u002Ffinalise-change",{"title":146,"path":147,"stem":148},"How to install the EOS Docs MCP server","\u002Feos\u002Fhow-to\u002Finstall-eos-docs-mcp","eos\u002Fhow-to\u002Finstall-eos-docs-mcp",{"title":150,"path":151,"stem":152},"How to resolve a spike ticket","\u002Feos\u002Fhow-to\u002Fresolve-spike-ticket","eos\u002Fhow-to\u002Fresolve-spike-ticket",{"title":154,"path":155,"stem":156},"How to run Git hook checks","\u002Feos\u002Fhow-to\u002Frun-git-hook-checks","eos\u002Fhow-to\u002Frun-git-hook-checks",{"title":158,"path":159,"stem":160},"How to use the AI-enabled SDLC","\u002Feos\u002Fhow-to\u002Fuse-ai-enabled-sdlc","eos\u002Fhow-to\u002Fuse-ai-enabled-sdlc",{"title":162,"path":163,"stem":164},"Use the Aikido plugin","\u002Feos\u002Fhow-to\u002Fuse-aikido-plugin","eos\u002Fhow-to\u002Fuse-aikido-plugin",{"title":166,"path":167,"stem":168},"How to use Compass","\u002Feos\u002Fhow-to\u002Fuse-compass","eos\u002Fhow-to\u002Fuse-compass",{"title":170,"path":171,"stem":172},"How to use Fallow","\u002Feos\u002Fhow-to\u002Fuse-fallow","eos\u002Fhow-to\u002Fuse-fallow",{"title":174,"path":175,"stem":176},"How to use incremental mutation tests","\u002Feos\u002Fhow-to\u002Fuse-incremental-mutation-tests","eos\u002Fhow-to\u002Fuse-incremental-mutation-tests",{"title":178,"path":179,"stem":180},"How to use Scout","\u002Feos\u002Fhow-to\u002Fuse-scout","eos\u002Fhow-to\u002Fuse-scout",{"title":97,"path":182,"stem":183,"children":184,"page":43},"\u002Feos\u002Freference","eos\u002Freference",[185,189,193,197],{"title":186,"path":187,"stem":188},"Compass CLI","\u002Feos\u002Freference\u002Fcompass-cli","eos\u002Freference\u002Fcompass-cli",{"title":190,"path":191,"stem":192},"EOS marketplace skills","\u002Feos\u002Freference\u002Fmarketplace-skills","eos\u002Freference\u002Fmarketplace-skills",{"title":194,"path":195,"stem":196},"Nx task execution and cache","\u002Feos\u002Freference\u002Fnx-task-execution","eos\u002Freference\u002Fnx-task-execution",{"title":198,"path":199,"stem":200},"Scout CLI","\u002Feos\u002Freference\u002Fscout-cli","eos\u002Freference\u002Fscout-cli",{"title":202,"path":203,"stem":204,"children":205},"Product engineering","\u002Fproduct-engineering","product-engineering\u002FREADME",[206],{"title":14,"collapsed":15,"path":207,"stem":208,"children":209,"page":43},"\u002Fproduct-engineering\u002Fadrs","product-engineering\u002Fadrs",[210],{"title":211,"path":212,"stem":213},"Codify Engineering Standards as Skills","\u002Fproduct-engineering\u002Fadrs\u002F0002-codify-engineering-standards-as-skills","product-engineering\u002Fadrs\u002F0002-codify-engineering-standards-as-skills",[215,268],{"nav":216,"source":265},[217],{"title":218,"path":219,"stem":220,"children":221},"Ember","\u002Fember","ember",[222,225,257,261],{"title":223,"path":219,"stem":224},"StoreFront Documentation","ember\u002Findex",{"title":14,"path":226,"stem":227,"children":228,"page":43},"\u002Fember\u002Fadrs","ember\u002Fadrs",[229,233,237,241,245,249,253],{"title":230,"path":231,"stem":232},"Add Infection as a non-blocking mutation testing tool for Ember","\u002Fember\u002Fadrs\u002F0001-infection-mutation-testing","ember\u002Fadrs\u002F0001-infection-mutation-testing",{"title":234,"path":235,"stem":236},"Process DELETE scheduled changes before CREATE_UPDATE at the same instant","\u002Fember\u002Fadrs\u002F0002-scheduled-change-processing-order","ember\u002Fadrs\u002F0002-scheduled-change-processing-order",{"title":238,"path":239,"stem":240},"Standard rate scheduling is permanent until overridden","\u002Fember\u002Fadrs\u002F0003-standard-rate-scheduling-is-permanent","ember\u002Fadrs\u002F0003-standard-rate-scheduling-is-permanent",{"title":242,"path":243,"stem":244},"Promotions require an existing standard rate","\u002Fember\u002Fadrs\u002F0004-promotions-require-existing-standard-rate","ember\u002Fadrs\u002F0004-promotions-require-existing-standard-rate",{"title":246,"path":247,"stem":248},"UTC datetime contract between Storefront and Hub","\u002Fember\u002Fadrs\u002F0005-utc-datetime-contract-between-storefront-and-hub","ember\u002Fadrs\u002F0005-utc-datetime-contract-between-storefront-and-hub",{"title":250,"path":251,"stem":252},"Elapsed unprocessed scheduled changes do not block rate changes","\u002Fember\u002Fadrs\u002F0006-stale-scheduler-rows-do-not-block-rate-changes","ember\u002Fadrs\u002F0006-stale-scheduler-rows-do-not-block-rate-changes",{"title":254,"path":255,"stem":256},"ADR-0007: Delete ConfigureTenantAuth routing command once OIDC setup migrates to Hub","\u002Fember\u002Fadrs\u002F0007-delete-configure-tenant-auth-routing-command","ember\u002Fadrs\u002F0007-delete-configure-tenant-auth-routing-command",{"title":258,"path":259,"stem":260},"Domain Overview","\u002Fember\u002Fdomain_overview","ember\u002Fdomain_overview",{"title":262,"path":263,"stem":264},"Main Flows","\u002Fember\u002Fkey_flows","ember\u002Fkey_flows",{"collectionName":266,"label":267,"prefix":220},"external_ember","StoreFront (Ember)",{"nav":269,"source":441},[270],{"title":271,"path":272,"stem":273,"children":274},"Core","\u002Fcore","core",[275,278,306,310,332,336,346,363,420,424],{"title":276,"path":272,"stem":277},"Documentation Index","core\u002Findex",{"title":14,"path":279,"stem":280,"children":281,"page":43},"\u002Fcore\u002Fadrs","core\u002Fadrs",[282,286,290,294,298,302],{"title":283,"path":284,"stem":285},"ADR-XXXX: Short, descriptive title","\u002Fcore\u002Fadrs\u002F0000-template","core\u002Fadrs\u002F0000-template",{"title":287,"path":288,"stem":289},"ADR-1: Promotions endpoint","\u002Fcore\u002Fadrs\u002F0001-add-promotions-endpoint","core\u002Fadrs\u002F0001-add-promotions-endpoint",{"title":291,"path":292,"stem":293},"ADR-2: EOM partner report job dispatch","\u002Fcore\u002Fadrs\u002F0002-eom-report-job-dispatch","core\u002Fadrs\u002F0002-eom-report-job-dispatch",{"title":295,"path":296,"stem":297},"ADR-3: Replace PB fee waive flag with a Zero scheme override","\u002Fcore\u002Fadrs\u002F0003-replace-pb-fee-waive-with-zero-scheme","core\u002Fadrs\u002F0003-replace-pb-fee-waive-with-zero-scheme",{"title":299,"path":300,"stem":301},"ADR-4: No processor Digital Top-up capability gate in Reloadable Commercials","\u002Fcore\u002Fadrs\u002F0004-no-processor-top-up-capability-gate","core\u002Fadrs\u002F0004-no-processor-top-up-capability-gate",{"title":303,"path":304,"stem":305},"ADR-5: Sparse polymorphic sale fee override reason stamp","\u002Fcore\u002Fadrs\u002F0005-sale-fee-override-reason-stamp","core\u002Fadrs\u002F0005-sale-fee-override-reason-stamp",{"title":307,"path":308,"stem":309},"Agent Workflow","\u002Fcore\u002Fai-workflow","core\u002Fai-workflow",{"title":311,"path":312,"stem":313,"children":314},"Backend Guide","\u002Fcore\u002Fbackend","core\u002Fbackend\u002Findex",[315,316,320,324,328],{"title":311,"path":312,"stem":313},{"title":317,"path":318,"stem":319},"Backend AI Tooling","\u002Fcore\u002Fbackend\u002Fai-tooling","core\u002Fbackend\u002Fai-tooling",{"title":321,"path":322,"stem":323},"Backend Linting and Formatting","\u002Fcore\u002Fbackend\u002Flinting-and-formatting","core\u002Fbackend\u002Flinting-and-formatting",{"title":325,"path":326,"stem":327},"Backend Setup","\u002Fcore\u002Fbackend\u002Fsetup","core\u002Fbackend\u002Fsetup",{"title":329,"path":330,"stem":331},"Backend Testing","\u002Fcore\u002Fbackend\u002Ftesting","core\u002Fbackend\u002Ftesting",{"title":333,"path":334,"stem":335},"Documentation Health","\u002Fcore\u002Fdoc-health","core\u002Fdoc-health",{"title":337,"path":338,"stem":339,"children":340},"Frontend Guide","\u002Fcore\u002Ffrontend","core\u002Ffrontend\u002Findex",[341,342],{"title":337,"path":338,"stem":339},{"title":343,"path":344,"stem":345},"Frontend Development","\u002Fcore\u002Ffrontend\u002Fdevelopment","core\u002Ffrontend\u002Fdevelopment",{"title":347,"path":348,"stem":349,"children":350,"page":43},"Modules","\u002Fcore\u002Fmodules","core\u002Fmodules",[351,355],{"title":352,"path":353,"stem":354},"Connect API","\u002Fcore\u002Fmodules\u002Fconnect-api","core\u002Fmodules\u002Fconnect-api",{"title":356,"path":357,"stem":358,"children":359,"page":43},"Secure Links","\u002Fcore\u002Fmodules\u002Fsecure-links","core\u002Fmodules\u002Fsecure-links",[360],{"title":356,"path":361,"stem":362},"\u002Fcore\u002Fmodules\u002Fsecure-links\u002Fsecure-links","core\u002Fmodules\u002Fsecure-links\u002Fsecure-links",{"title":364,"path":365,"stem":366,"children":367,"page":43},"Processors","\u002Fcore\u002Fprocessors","core\u002Fprocessors",[368,372,376,380,384,388,392,396,400,404,408,412,416],{"title":369,"path":370,"stem":371},"Amazon Processor and API","\u002Fcore\u002Fprocessors\u002Famazon","core\u002Fprocessors\u002Famazon",{"title":373,"path":374,"stem":375},"Amilon Processor and API","\u002Fcore\u002Fprocessors\u002Familon","core\u002Fprocessors\u002Familon",{"title":377,"path":378,"stem":379},"Cadooz Processor and API","\u002Fcore\u002Fprocessors\u002Fcadooz","core\u002Fprocessors\u002Fcadooz",{"title":381,"path":382,"stem":383},"Choice Digital Processor and API","\u002Fcore\u002Fprocessors\u002Fchoice-digital","core\u002Fprocessors\u002Fchoice-digital",{"title":385,"path":386,"stem":387},"Diggecard processor reference","\u002Fcore\u002Fprocessors\u002Fdiggecard","core\u002Fprocessors\u002Fdiggecard",{"title":389,"path":390,"stem":391},"ePay Processor and API","\u002Fcore\u002Fprocessors\u002Fepay","core\u002Fprocessors\u002Fepay",{"title":393,"path":394,"stem":395},"GoGift v2 Processor and API","\u002Fcore\u002Fprocessors\u002Fgo-gift-v2","core\u002Fprocessors\u002Fgo-gift-v2",{"title":397,"path":398,"stem":399},"InComm Processor and API","\u002Fcore\u002Fprocessors\u002Fincomm","core\u002Fprocessors\u002Fincomm",{"title":401,"path":402,"stem":403},"Ogloba Processor and API","\u002Fcore\u002Fprocessors\u002Fogloba","core\u002Fprocessors\u002Fogloba",{"title":405,"path":406,"stem":407},"SVSECard Processor and API","\u002Fcore\u002Fprocessors\u002Fsvs-ecard","core\u002Fprocessors\u002Fsvs-ecard",{"title":409,"path":410,"stem":411},"Vananam Processor and API","\u002Fcore\u002Fprocessors\u002Fvananam","core\u002Fprocessors\u002Fvananam",{"title":413,"path":414,"stem":415},"Vouchers Depot processor reference","\u002Fcore\u002Fprocessors\u002Fvouchers-depot","core\u002Fprocessors\u002Fvouchers-depot",{"title":417,"path":418,"stem":419},"You Got a Gift Processor and API","\u002Fcore\u002Fprocessors\u002Fyou-got-a-gift","core\u002Fprocessors\u002Fyou-got-a-gift",{"title":421,"path":422,"stem":423},"Development Quickstart","\u002Fcore\u002Fsetup","core\u002Fsetup",{"title":425,"path":426,"stem":427,"children":428,"page":43},"Workflows","\u002Fcore\u002Fworkflows","core\u002Fworkflows",[429,433,437],{"title":430,"path":431,"stem":432},"Hub Endpoint Workflow","\u002Fcore\u002Fworkflows\u002Fhub-endpoints","core\u002Fworkflows\u002Fhub-endpoints",{"title":434,"path":435,"stem":436},"OpenAPI Tooling","\u002Fcore\u002Fworkflows\u002Fopenapi-tooling","core\u002Fworkflows\u002Fopenapi-tooling",{"title":438,"path":439,"stem":440},"Processor Integration Workflow","\u002Fcore\u002Fworkflows\u002Fprocessors","core\u002Fworkflows\u002Fprocessors",{"collectionName":442,"label":271,"prefix":273},"external_core",{"page":444,"surround":679},{"id":445,"title":68,"body":446,"config":674,"description":452,"extension":675,"meta":676,"navigation":15,"path":69,"seo":677,"stem":70,"__hash__":678},"docs\u002Feos\u002Fharbourmaster\u002Fexplanation\u002Fshared-action-trust-boundary.md",{"type":447,"value":448,"toc":663},"minimark",[449,453,468,473,480,485,500,503,507,518,528,534,538,541,548,552,559,562,566,569,572,576,582,593,620,623,629,634,637,652],[450,451,452],"p",{},"Harbourmaster runs repository code analysis inside a GitHub Actions job that can\nrequest an AWS OIDC token and publish pull request feedback. Its workflow design\ntherefore treats executable references, event context, and repository checkout\nstate as parts of one trust boundary.",[450,454,455,456,467],{},"The design was exercised while adding Harbourmaster to\n",[457,458,462,466],"a",{"href":459,"rel":460},"https:\u002F\u002Fgithub.com\u002FTilloTech\u002Fgo\u002Fpull\u002F76",[461],"nofollow",[463,464,465],"code",{},"TilloTech\u002Fgo"," pull request 76",". The\nreview exposed several principles that apply to every consuming repository.",[469,470],"content-mermaid-transport",{":page-config":471,"code":472},"config","flowchart%20LR%0A%20%20%20%20Event%5B%22pull_request%20event%22%5D%20--%3E%20Guard%7B%22Same%20repository%20and%20not%20draft%3F%22%7D%0A%20%20%20%20Guard%20--%3E%7C%22No%22%7C%20Skip%5B%22Do%20not%20run%20a%20review%22%5D%0A%20%20%20%20Guard%20--%3E%7C%22Yes%22%7C%20Request%7B%22Label%20absent%20or%20explicitly%20re-added%3F%22%7D%0A%20%20%20%20Request%20--%3E%7C%22No%22%7C%20Skip%0A%20%20%20%20Request%20--%3E%7C%22Yes%22%7C%20Label%5B%22Apply%20harbourmaster-review%20label%22%5D%0A%20%20%20%20Label%20--%3E%20Checkout%5B%22Checkout%20exact%20reviewed%20head%20SHA%22%5D%0A%0A%20%20%20%20Action%5B%22Harbourmaster%20action%20from%20EOS%20main%22%5D%20--%3E%20Runner%0A%20%20%20%20Checkout%20--%3E%20Runner%5B%22Trusted%20Harbourmaster%20runner%22%5D%0A%20%20%20%20Runner%20--%3E%7C%22Scoped%20patch%20workspace%22%7C%20OpenCode%5B%22OpenCode%20agents%22%5D%0A%20%20%20%20Runner%20--%3E%7C%22OIDC%20role%22%7C%20Bedrock%5B%22Amazon%20Bedrock%22%5D%0A%20%20%20%20Runner%20--%3E%7C%22Octokit%20reads%20and%20verification%22%7C%20GitHub%5B%22GitHub%20pull%20request%22%5D%0A%0A%20%20%20%20OpenCode%20--%3E%7C%22Trusted%20local%20publication%20plugin%22%7C%20GitHub%0A%20%20%20%20OpenCode%20-.-%3E%7C%22Raw%20process%20logs%22%7C%20Runner%0A%20%20%20%20Bedrock%20-.-%3E%7C%22Model%20responses%22%7C%20Runner",[450,474,475,476,479],{},"The primary ",[463,477,478],{},"harbourmaster-review-editor"," session acts as the coordinator. It\ninvokes the specialist and verifier sessions, and it is the only session that\ncan publish to GitHub through one local publication tool configured by the\ntrusted action. The tool validates a runner-authored manifest, publishes the\nreview, applies prior-thread dispositions, and writes a private receipt.\nOpenCode starts in an isolated diff directory with the trusted bundled\nconfiguration. The code-quality reviewer alone also has read-only access to the\nwhole canonical checkout. Other specialists and the verifier remain limited to\nthe staged diff. Consumer OpenCode configuration remains untrusted review\ncontext and cannot execute. For each editor attempt, the runner passes the\nresolved GitHub token only in the OpenCode process environment. The trusted\npublication plugin uses that process-level token. Specialist and verifier\nsessions have no publication or GitHub tools and receive no token in their\nsession inputs. The runner verifies a new marked review on the exact head SHA\nafter OpenCode exits.",[481,482,484],"h2",{"id":483},"runtime-references-follow-repository-role","Runtime references follow repository role",[450,486,487,488,491,492,495,496,499],{},"Consumer repositories invoke ",[463,489,490],{},"TilloTech\u002Feos\u002Fapps\u002Fharbourmaster@main",". They\ntherefore receive only Harbourmaster changes that have merged to the EOS ",[463,493,494],{},"main","\nbranch. The EOS repository invokes its local ",[463,497,498],{},".\u002Fapps\u002Fharbourmaster"," action from\nthe pull request head so changes to Harbourmaster can be tested before merge.",[450,501,502],{},"The checkout action remains pinned separately because it prepares the reviewed\nworkspace inside the OIDC-enabled job. EOS owns the transitive action\ndependencies inside Harbourmaster and reviews their pins before changing them.",[481,504,506],{"id":505},"event-and-checkout-identity-must-agree","Event and checkout identity must agree",[450,508,509,510,513,514,517],{},"The ",[463,511,512],{},"pull_request"," event supplies context to a workflow that owns both label\ncreation and review execution. A job guard excludes drafts and forks before\ncheckout or credentials are available. Automatic events run only while\n",[463,515,516],{},"harbourmaster-review"," is absent; explicitly re-adding that label requests\nanother review. When the label is already present, the job emits a warning and\nfails before checkout so a required Harbourmaster check blocks the unreviewed\nhead. A human must remove and re-add the label to request re-review; automation\nmust not do so. The job receives the pull request number and exact head SHA\ndirectly from that guarded event.",[450,519,520,521,524,525,527],{},"Harbourmaster verifies the checked-out Git HEAD against ",[463,522,523],{},"head_sha"," before\nstarting reviewers. This couples the review result to the code that triggered\nthe run and prevents a stale or implicit branch reference from changing the\nreview target. Consumer repositories load the Harbourmaster action from EOS\n",[463,526,494],{},". EOS self-reviews load the local action from the exact pull request head\nso runtime changes are exercised before merge.",[450,529,530,533],{},[463,531,532],{},"pull_request_target"," would move workflow execution into the privileged base\nrepository context. Combining that event with checkout of untrusted head code\nwould cross the intended trust boundary, so Harbourmaster consumer workflows do\nnot use it.",[481,535,537],{"id":536},"security-policy-needs-executable-checks","Security policy needs executable checks",[450,539,540],{},"The fork and draft guards, exact-head checkout, least-privilege permissions,\ndisabled credential persistence, and runtime reference policy are security\ncontrols, not formatting conventions. Documentation records their purpose, but\ntests and workflow policy checks detect accidental removal or inversion.",[450,542,543,544,547],{},"EOS tests the shared action's packaging and its own workflow structure. A\nconsuming repository remains responsible for checking its workflow, including\nthe event, fork and draft guard, permissions, checkout SHA, and\n",[463,545,546],{},"persist-credentials: false"," setting.",[481,549,551],{"id":550},"operator-configuration-belongs-in-operator-documentation","Operator configuration belongs in operator documentation",[450,553,554,555,558],{},"An implementation specification can explain why an OIDC role is required, but it\nis not the setup interface for repository operators. The required\n",[463,556,557],{},"HARBOURMASTER_AWS_ROLE_TO_ASSUME"," variable must be discoverable beside the\nworkflow setup, including where it is configured and what value it accepts.",[450,560,561],{},"This separation keeps intent records stable while allowing operational guidance\nto evolve with the supported action contract.",[481,563,565],{"id":564},"portable-records-preserve-traceability","Portable records preserve traceability",[450,567,568],{},"Repository-relative paths and commit-anchored GitHub links remain resolvable by\nother contributors and CI. Machine-specific absolute paths only describe one\nauthor's checkout and weaken the connection between an implementation record and\nthe files it references.",[450,570,571],{},"Cross-repository records identify both the repository and relative path, or use\na permalink at the reviewed commit. This keeps the evidence behind trust\ndecisions inspectable after the original workspace no longer exists.",[481,573,575],{"id":574},"eos-self-review-is-an-invariant","EOS self-review is an invariant",[450,577,578,579,581],{},"Consumer repositories must load the Harbourmaster action from EOS ",[463,580,494],{},". EOS is\nthe deliberate exception: Harbourmaster must be able to test changes to its own\nworkflow and runtime before those changes merge.",[450,583,584,585,588,589,592],{},"For a same-repository, non-draft pull request in ",[463,586,587],{},"TilloTech\u002Feos",",\n",[463,590,591],{},"harbourmaster-review.yml"," must:",[594,595,596,600,607,613],"ul",{},[597,598,599],"li",{},"check out the pull request head as the Harbourmaster runtime workspace;",[597,601,602,603,606],{},"check out the same head SHA again at ",[463,604,605],{},".harbourmaster\u002Frepository",";",[597,608,609,610,612],{},"invoke the local ",[463,611,498],{}," action;",[597,614,615,616,619],{},"pass ",[463,617,618],{},"workspace_root: .harbourmaster\u002Frepository",".",[450,621,622],{},"The action verifies that the reviewed checkout's Git HEAD equals the requested\nSHA before reviewer execution. Fork pull requests remain excluded by the job\nguard.",[450,624,625,626,628],{},"Consumer workflows check out the reviewed head once and invoke\n",[463,627,490],{},". They must not copy the EOS dual\ncheckout or the local action path. The consumer checkout pin can differ from the\nEOS pin. EOS owns the pins inside the Action.",[450,630,631,632,619],{},"This exception intentionally allows an EOS pull request to change code that runs\nwith the reviewer job's GitHub and AWS permissions. That tradeoff is limited to\nbranches in the EOS repository, where push access is already trusted. It must\nnot be generalized to consumer repositories or implemented with\n",[463,633,532],{},[450,635,636],{},"The following behavior is therefore a repository invariant:",[594,638,639,644,649],{},[597,640,641,642,619],{},"EOS self-reviews execute the local action from the exact pull request head and\nreview the checkout at ",[463,643,605],{},[597,645,646,647,619],{},"Consumer reviews execute the Harbourmaster action from EOS ",[463,648,494],{},[597,650,651],{},"Both paths use the native pull request job's same-repository and non-draft\nguard, pass the event's exact head SHA, and verify the reviewed checkout\nagainst it.",[450,653,654,655,658,659,619],{},"For the consumer workflow, see\n",[457,656,77],{"href":657},"..\u002Fhow-to\u002Fadd-harbourmaster-to-a-repository",".\nThe original auth and fork decision is in\n",[457,660,662],{"href":661},"..\u002Fdecisions\u002Fai-50-auth-and-fork-policy","AI-50",{"title":664,"searchDepth":665,"depth":665,"links":666},"",3,[667,669,670,671,672,673],{"id":483,"depth":668,"text":484},2,{"id":505,"depth":668,"text":506},{"id":536,"depth":668,"text":537},{"id":550,"depth":668,"text":551},{"id":564,"depth":668,"text":565},{"id":574,"depth":668,"text":575},{},"md",{},{"title":68,"description":452},"lYCRyBuCa2XneM2_1-BuB7sPKwFOpuxtvmYSTMf36Fk",[680,681],{"title":64,"path":65,"stem":66,"children":-1},{"title":77,"path":78,"stem":79,"children":-1},1789777547920]