Skip to content

Allow the exact Global ETF job workflow identity - #241

Merged
Pigbibi merged 1 commit into
mainfrom
fix/global-etf-job-workflow-auth
Sep 16, 2026
Merged

Pigbibi merged 1 commit into
mainfrom
fix/global-etf-job-workflow-auth

Conversation

@Pigbibi

@Pigbibi Pigbibi commented Sep 16, 2026

Copy link
Copy Markdown
Contributor

The auth-only run 35135230905 identified service HTTP 401 with job_workflow_ref_not_allowed. GitHub supplies this second identity claim for the Global ETF workflow; its workflow_ref was already permitted, but the job allowlist omitted it.

Add only the exact Global ETF main job-workflow identity to both deployment sources. Keep all other entries and the first allowlist unchanged. Regression tests exercise the actual two-claim payload and reject other branches and job workflows.

Validation: 29 focused tests passed, 1 skipped, 19 subtests; actionlint, Ruff, Bash syntax and diff checks passed. No research/model execution or trading changes.

Co-Authored-By: Codex <noreply@openai.com>
@Pigbibi
Pigbibi merged commit 630575c into main Sep 16, 2026
4 checks passed
@Pigbibi
Pigbibi deleted the fix/global-etf-job-workflow-auth branch September 16, 2026 18:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant