diff --git a/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md b/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md index 1c964cbce..6c87123e8 100644 --- a/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md +++ b/docs/decisions/records/ci/pr-route-carries-no-stored-credential.md @@ -97,7 +97,10 @@ faulted by name. So a `secrets:` key whose value is not a mapping now faults und sentinel, judged on the VALUE SHAPE rather than on the word `inherit`, for the reason the residue counter does not match `toJSON` by name. Unlike the spelling gaps this one is invisible to the text cross-check for a reason no widening of `secret_refs` fixes — there is no text for its half to match -— so the clause reads the document only, and says so where it is defined. +— so the clause reads the document only, and says so where it is defined. Whether act_runner on this +instance resolves `workflow_call` + `secrets: inherit` at all was NOT probed (2026-09-05); that +governs reachability today, not the guard's silence, and the direction is the one every spelling row +already takes — an unsupported shape costs a spurious demand on a job nobody has written. **The `if:` classifier is a PIN, not a parser.** Exactly one string — `github.event_name != 'pull_request'` — takes a job off the route. Anything else, including