Actually, this is a security issue. My initial evaluation was wrong. Because you could have hooks running resource actions with authorize?: false, and have been relying on the update policies to prevent those side effects. I will issue a CVE for affected AshPostgres versions when I am back at my computer in a few hours, and I will also see if there is a way to programmatically identify actions that may have been affected.






















