Summary
WORKFLOW.md D4.1 states in bold that "A human merge never auto-publishes", with no exception. The D4.7 supersede step leaves a window where one does: a push landing after the step's git ls-remote re-check and before gh workflow run is built and released by the dispatched run without the actor-allowlist check, since a dispatch runs whatever the branch head is when it is created. That push can be a human merge.
The #2009 change names this window in D4.7 and S14. It leaves D4.1 unchanged, because the same unqualified wording is stated on several other surfaces, and qualifying one of them alone would put them in disagreement.
Surfaces carrying the unqualified wording
WORKFLOW.md D4.1, and the section 3 overview sentence "A human merge never auto-publishes"
.agents/skills/branching-and-release-model/SKILL.md, and its generated copies
docs/reusable-workflows.md, which cites D4.1 for it
- the header comment in
.github/workflows/publish-plan-task.yml
GOVERNANCE.md "Release Model" says "a human merge never auto-publishes on its own", which arguably still holds, since in the window the merge rides a bot's re-dispatch.
Suggested direction
Either qualify every surface above consistently, naming the D4.7 window as the one exception, or close the window itself, for example by passing the checked SHA through a dispatch input so the dispatched run refuses a head that moved. The second is a behavior change on every publisher stub.
Found by a local strict-review pass while working #2009.
Summary
WORKFLOW.mdD4.1 states in bold that "A human merge never auto-publishes", with no exception. The D4.7 supersede step leaves a window where one does: a push landing after the step'sgit ls-remotere-check and beforegh workflow runis built and released by the dispatched run without the actor-allowlist check, since a dispatch runs whatever the branch head is when it is created. That push can be a human merge.The #2009 change names this window in D4.7 and S14. It leaves D4.1 unchanged, because the same unqualified wording is stated on several other surfaces, and qualifying one of them alone would put them in disagreement.
Surfaces carrying the unqualified wording
WORKFLOW.mdD4.1, and the section 3 overview sentence "A human merge never auto-publishes".agents/skills/branching-and-release-model/SKILL.md, and its generated copiesdocs/reusable-workflows.md, which cites D4.1 for it.github/workflows/publish-plan-task.ymlGOVERNANCE.md"Release Model" says "a human merge never auto-publishes on its own", which arguably still holds, since in the window the merge rides a bot's re-dispatch.Suggested direction
Either qualify every surface above consistently, naming the D4.7 window as the one exception, or close the window itself, for example by passing the checked SHA through a dispatch input so the dispatched run refuses a head that moved. The second is a behavior change on every publisher stub.
Found by a local strict-review pass while working #2009.