Codex P1: the previous head-only rejection refused EVERY new entry,
making the documented "land the allowlist delta on main first"
workflow unreachable via PR. Any PR that proposed a new trusted
entry was permanently red.
The threat the gate is meant to catch is narrow: a single PR that
adds a new install-script dependency AND allowlists it in the same
diff, so the dep can ship without being eyeballed. Allowlist
additions that do NOT match any new install-script finding in this
PR's lockfile diff are harmless on their own -- they just prepare
the trust list. A follow-up PR that actually adds the dep then
sees the trusted entry on base and passes normally.
Narrow the check accordingly:
self_approving = head_only_entries & current_install_script_findings
if self_approving: FAIL
Existing protections remain:
* head_only entries that DO match a current finding still fail
(the self-approval bypass).
* head DROPPING base entries still fails (closes the
delete-then-bootstrap exploit).
* Bootstrap mode (base file missing entirely) still accepts head
as-is so the very first PR to introduce the file can land.
Sanity-tested: adding an unused entry now passes; dropping a base
entry still fails; bootstrap + esbuild@0.21.5 still passes (this
PR's own CI shape).