Measured 2026-09-10 in a worker session on #396, while trying to confirm whether actions/dependency-review-action supports the merge_group event.
| target |
result |
github.com/actions/dependency-review-action/blob/main/README.md |
❌ EGRESS_BLOCKED, domain github.com |
docs.github.com/... (two separate pages) |
✅ 200, content returned |
Why this is worth a line. #112's egress table records github.com/empathic/toolpath as ❌ 403 (out of repo scope). That attribution is wrong, or at least no longer the operative cause: the proxy refuses the domain, so scope never enters into it. A session reading that table would conclude an in-scope github.com URL is fetchable. It is not.
The consequence that bit. "Does this action support event X" is a routine verification, and the answer normally lives in the action's README on github.com. From a session it cannot be read at all. On #396 this left the dependency-review + merge_group question explicitly unmeasured rather than answered — the honest outcome, but one every future session will re-derive.
Options, smallest first: correct #112's table in place; or add github.com (raw README paths at minimum) to the allowlist; or vendor the handful of action READMEs the org pins. No preference asserted — the measurement is the contribution here.
Measured 2026-09-10 in a worker session on #396, while trying to confirm whether
actions/dependency-review-actionsupports themerge_groupevent.github.com/actions/dependency-review-action/blob/main/README.mdEGRESS_BLOCKED, domaingithub.comdocs.github.com/...(two separate pages)Why this is worth a line. #112's egress table records
github.com/empathic/toolpathas❌ 403 (out of repo scope). That attribution is wrong, or at least no longer the operative cause: the proxy refuses the domain, so scope never enters into it. A session reading that table would conclude an in-scopegithub.comURL is fetchable. It is not.The consequence that bit. "Does this action support event X" is a routine verification, and the answer normally lives in the action's README on
github.com. From a session it cannot be read at all. On #396 this left thedependency-review+merge_groupquestion explicitly unmeasured rather than answered — the honest outcome, but one every future session will re-derive.Options, smallest first: correct #112's table in place; or add
github.com(raw README paths at minimum) to the allowlist; or vendor the handful of action READMEs the org pins. No preference asserted — the measurement is the contribution here.