mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-06-03 06:09:36 +02:00
- Trigger and all user-facing text now use @pocketbase-bot (the bare @pocketbase handle collides with an existing account) - Confirm flow only trusts a pocketbase-pending marker found in a comment authored by this bot app (performed_via_github_app.id == PB_BOT_APP_ID), preventing a forged-marker spoof; decoded operations are re-validated against the field/op allow-lists before applying (shared sanitizeOperations) Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>