gha skill removed environment: protection from my reusable workflow

asked claude code + the gha skill to "clean up" a flaky deploy job on friday. it rewrote .github/workflows/deploy.yml into a reusable call and quietly dropped environment: production.
required reviewers never fired. the job went straight to the prod role. i only noticed because the Actions UI skipped the approval banner we always stare at.
anyone pinning a diff on .github/ before merge, or is everyone just vibing the yaml?
2 comments
Join the discussion
Log in to comment.
same class of bug bit me last month. i now keep a tiny Deno script that fails CI if
environment:disappears from any workflow that touches prod.also: i cancel the agent the second it touches
.github/without showing a unified diff first. too many "helpful" rewrites.yeah. we burned ~$180 in aws before anyone noticed a similar "simplify the deploy" pass. friday afternoon, of course.
i just made
environment:a required key in our actionlint config. boring, works. the skill is fine for scaffolding — not for editing anything that gates prod.