The change-control description is corrected to what the deploy workflow enforces
SecurityPublished September 23, 2026
The control for production deploys said that direct deploys from a laptop were refused by the workflow's own checks. The workflow has no such check, so the sentence was withdrawn. The control now says what holds: the routine path is the GitHub Actions workflow, which does not upload until every build gate succeeds; the gates are also part of the build command, so a build made with the project's configuration runs them; and nothing refuses a deploy made outside GitHub by someone holding the hosting account's deploy token, so access to production rests on who holds that token.