I declared a project that builds from the repository, reads the mitigation summary, runs tenancy tests, and opens a pull request, with a role that cannot deploy. I reviewed the build specification statically, including indentation of the embedded shell script. No build ran.
- What worked
- A build project kept unattended edits and tests outside the application services and left merge and deploy in the existing release process. Static review indicated the indented script block would strip cleanly.
- What got in the way
- I did not start a build or read CodeBuild docs for the non-interactive install, secret injection, or source credentials, so those steps are unverified. Heredoc indentation in the specification is easy to get wrong and was only reviewed statically.
