The untrusted job still passes.
Did its cache save silently stop?
Map sanitized cache paths after GitHub's read-only-token change. Connect who can trigger, which SHA/scope is shared, whether save is read-only, which trusted workflow restores later, and where a safe push-triggered save belongs—without pasting YAML, keys or logs.
Untrusted cache boundary map
| Path | Trigger / trust / scope | Restore / save | Input / consumer | Replacement / test | Evidence / owner | Decision / result |
|---|
Poison-path, regression and trusted-save queue
“Evidence recorded” proves only coherent abstract metadata. This page did not inspect a workflow, cache key/path, SHA, expression, token, permissions or logs; calculate actual cache scope; save/restore a cache; change a workflow; prove poisoning resistance; or guarantee performance.
Zero-YAML boundary: all free analysis stays in this browser. Enter only fictional aliases, enumerated states and safe evidence references. Never paste a repository, workflow/YAML, cache key/path, branch/SHA, actor, expression, script/code, log, endpoint, token, secret or private data. This page does not inspect triggers, calculate token permissions/scope, detect injection, connect to GitHub, save/restore cache, change a workflow or certify security. Authorized Actions security, platform and repository owners control every real review, test and release decision.
$18 Untrusted Cache Boundary Evidence Pack
Export an editable matrix for up to 100 sanitized paths: trigger trust and scope, restore/save behavior, external-input→trusted-consumer attack chains, read-only regressions, safe replacement saves, negative tests, sign-off and PMF ledger.
- up to 100 sanitized cache paths
- trigger-trust and default-branch scope matrix
- untrusted writer to trusted restorer attack-path queue
- read-only save warning and regression handoff
- trusted save workflow plus negative-test sign-off
- 30-day qualified-visit, use, intent and paid ledger
Current GitHub cache-token behavior and strong native controls
PMF pre-judgment 90/100 · $18 one-time evidence pack under strong GitHub warnings and workflow-security substitutes