fix: restrict bonk commands to repo members, collaborators, and owners#327
fix: restrict bonk commands to repo members, collaborators, and owners#327james-elicx merged 1 commit intomainfrom
Conversation
|
/bigbonk review this pr |
commit: |
|
|
This PR is straightforward and correct. Here's my review: Changes look good. Both A few specific observations:
No issues found. This is a clean security hardening change. |
Summary
author_associationcheck to bothbonk.ymlandbigbonk.yml, matching the existing pattern indeploy-preview-command.yml/bonk,@ask-bonk, and/bigbonkcan now only be triggered byMEMBER,COLLABORATOR, orOWNER— preventing arbitrary users from invoking the AI agent