# Managed by deploy-ansipa-git-pull.yml — do not edit by hand. # # Scoped to one exact command, no arguments, no argument substitution: a # compromised _ansipa account can invoke the enforcer (which only does what # the last GPG-signature-verified, fast-forward commit told it to) and # nothing else — it cannot pivot to arbitrary root execution. _ansipa ALL=(root) NOPASSWD: /usr/local/bin/ansipa-enforce-policies.sh