Workflow scripts only run from paths you can already read, and refusals say why.
What's wrong with this entry?
A workflow script path is now refused unless it is a path the tool itself returned or a file you can already read, meaning one under the working directory or an added directory. The refusal states the rule explicitly instead of the path being used silently.
- Applies unconditionally, with no flag to relax it.
scriptPath must be a script path this tool returned, or a file you can already read
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.239
Workflow tool gains run operations, with the auto-approval hook switched off
Both mention workflow
-
v2.1.239
Workflow tool has a second command shape built in but switched off
Both mention workflow
-
v2.1.239
Workflow "v2 run" handles are scaffolded but never created
Both mention workflow