chore(ci): tighten CODEOWNERS + drop overclaim in workflow comment
Round-3 PR re-review follow-ups: LOW — CODEOWNERS missed /scripts/build-plugins-index.mjs and /wrangler.toml. Both can change the bytes that get signed without touching the sign step. Replaced the per-file enumeration with /scripts/ catch-all and added wrangler.toml. HIGH — workflow comment said the post-sign verify step "catches a buggy or tampered sign-script run". The "tampered" claim was wrong: any attacker who can edit sign-plugins-index.mjs in a PR can edit the verify step (and the embedded pubkey) in the same diff. Re-stated as "catches accidental regressions only — CODEOWNERS is what stops adversarial edits". Branch protection on main has been enabled separately via gh API (force-push + deletion blocked, PR review required, CODEOWNERS enforced; bypass for repo owner and github-actions[bot] so the auto-publish workflow keeps working).
This commit is contained in:
1 parent
786cbd496a
commit
fe15ae5243
2 files changed
+14
-8
No files matched your search
+5
-3
@@ -19,11 +19,13 @@
|
||||
# - restrict who can push directly to main (org admins only)
|
||||
|
||||
# ---- Signing infrastructure (highest sensitivity) ----
|
||||
/scripts/sign-plugins-index.mjs @suzukaze-haduki
|
||||
/scripts/build-plugins-index.mjs @suzukaze-haduki
|
||||
/scripts/build-registry-index.mjs @suzukaze-haduki
|
||||
# Anything that influences the bytes that get signed, OR the signing
|
||||
# step itself, requires owner approval. Build-script edits change the
|
||||
# bytes that get signed even though they don't touch the sign step.
|
||||
/scripts/ @suzukaze-haduki
|
||||
/.github/workflows/ @suzukaze-haduki
|
||||
/.github/CODEOWNERS @suzukaze-haduki
|
||||
/wrangler.toml @suzukaze-haduki
|
||||
|
||||
# ---- Auto-generated artefacts (must not be hand-edited) ----
|
||||
/plugins-index.json @suzukaze-haduki
|
||||
|
||||
Reference in new issue
Block a user