Listing artifacts no longer asks you for permission first.
What's wrong with this entry?
The Artifact tool's list action used to require a one-time confirmation per session, with separate prompts for the shared and all scopes. That branch is gone and listing is permitted outright as a read-only action in every scope.
Listing artifacts published by or shared with the user is a read-only action
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.