Skip to content

PULL_REQUEST_TEMPLATE.md in doc-only allowlist could bypass required checklist changes #49

Description

@twistedmelonman

Non-Blocking Review Concern: PULL_REQUEST_TEMPLATE.md in doc-only allowlist could bypass required checklist changes

Source: claude (self-review bot)
Location: .github/workflows/claude-blocking-review.yml
PR: #47 — feat: doc-only fast-skip + SHA marker + prior-comment collapse (#47)
Date: 2026-04-18

What was flagged

.github/PULL_REQUEST_TEMPLATE.md is treated as doc-only, but PR templates can embed reviewer checklists, required sign-offs, or label instructions. A template change that removes a required security checklist would sail through with no review. Worth discussing whether to treat it like CODEOWNERS (excluded) rather than prose.

Context

This issue was automatically created from a non-blocking concern identified
during pre-merge review of PR #47. It was safe to merge but worth tracking.


Created by lib-review-issues.sh

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    tech-debtTechnical debt to address

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions