Question
What isolated execution environment may run untrusted repository code, which GitHub and provider credentials it receives, how it writes a branch and draft PR, and which facts or artefacts may cross from that sandbox into the read-only Cloud Reviewer boundary?
Question
What isolated execution environment may run untrusted repository code, which GitHub and provider credentials it receives, how it writes a branch and draft PR, and which facts or artefacts may cross from that sandbox into the read-only Cloud Reviewer boundary?