chore(ci): tighten CODEOWNERS + drop overclaim in workflow comment
Round-3 PR re-review follow-ups: LOW — CODEOWNERS missed /scripts/build-plugins-index.mjs and /wrangler.toml. Both can change the bytes that get signed without touching the sign step. Replaced the per-file enumeration with /scripts/ catch-all and added wrangler.toml. HIGH — workflow comment said the post-sign verify step "catches a buggy or tampered sign-script run". The "tampered" claim was wrong: any attacker who can edit sign-plugins-index.mjs in a PR can edit the verify step (and the embedded pubkey) in the same diff. Re-stated as "catches accidental regressions only — CODEOWNERS is what stops adversarial edits". Branch protection on main has been enabled separately via gh API (force-push + deletion blocked, PR review required, CODEOWNERS enforced; bypass for repo owner and github-actions[bot] so the auto-publish workflow keeps working).
This commit is contained in:
1 parent
786cbd496a
commit
fe15ae5243
2 files changed
+14
-8
No files matched your search
@@ -83,11 +83,15 @@ jobs:
|
||||
REGISTRY_PRIVATE_KEY: ${{ secrets.REGISTRY_PRIVATE_KEY }}
|
||||
run: node scripts/sign-plugins-index.mjs
|
||||
|
||||
# Defense in depth: verify the signature locally against the
|
||||
# public key (committed in this repo as REGISTRY_PUBLIC_KEY env)
|
||||
# before the .sig hits main. Catches a buggy or tampered
|
||||
# sign-script run; closes PR re-review on the in-repo signing
|
||||
# path. No secret material here.
|
||||
# Defense in depth: verify the signature against the committed
|
||||
# pubkey before the .sig hits main. This catches an *accidental*
|
||||
# sign-script regression — a malformed signature, an env-leak that
|
||||
# produces zero bytes, an off-by-one in the JSON canonicalization.
|
||||
# It does NOT defend against an adversary, because an attacker
|
||||
# who can edit sign-plugins-index.mjs in a PR can edit this verify
|
||||
# step and the embedded pubkey in the same diff. The CODEOWNERS
|
||||
# gate on `/scripts/` and `/.github/workflows/` is what stops
|
||||
# adversarial edits, not this step.
|
||||
- name: Verify signature against committed pubkey
|
||||
env:
|
||||
REGISTRY_PUBLIC_KEY: ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
|
||||
|
||||
Reference in new issue
Block a user