Skip to content

feat(lint): os validate refuses an api flow with no per-flow secret #29150

feat(lint): os validate refuses an api flow with no per-flow secret

feat(lint): os validate refuses an api flow with no per-flow secret #29150

Triggered via pull request September 29, 2026 08:35
Status Success
Total duration 1m 12s
Artifacts –

pr-automation.yml

on: pull_request
Check PR Size
Check PR Size
Check Changeset
1m 8s
Check Changeset
Auto Label
0s
Auto Label
Fit to window
Zoom out
Zoom in

Annotations

2 notices
Check Changeset: .changeset/20553-validate-api-flow-secret.md#L0
ADR-0087 exemption (no-migration-prescription): Nothing authorable changes spelling or type: `packages/spec` is untouched, and the start node `config` stays the open record it was. What changes is that three authoring commands, `os validate` / `os build` / `os lint`, now refuse one authored shape: an `api`-bound flow whose start node carries no usable `config.secret`. `objectstack migrate meta` could not rewrite that shape even in principle, because the missing value is a shared secret only the author and the sending system can supply. A stored flow of that shape has been refused at registration by `@objectstack/service-automation` since 17.5.0, whose published changelog entry records that load path's disposition; nothing here judges a stored row.
Check Changeset
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"