chore(ci): tighten CODEOWNERS + drop overclaim in workflow comment
Round-3 PR re-review follow-ups: LOW — CODEOWNERS missed /scripts/build-plugins-index.mjs and /wrangler.toml. Both can change the bytes that get signed without touching the sign step. Replaced the per-file enumeration with /scripts/ catch-all and added wrangler.toml. HIGH — workflow comment said the post-sign verify step "catches a buggy or tampered sign-script run". The "tampered" claim was wrong: any attacker who can edit sign-plugins-index.mjs in a PR can edit the verify step (and the embedded pubkey) in the same diff. Re-stated as "catches accidental regressions only — CODEOWNERS is what stops adversarial edits". Branch protection on main has been enabled separately via gh API (force-push + deletion blocked, PR review required, CODEOWNERS enforced; bypass for repo owner and github-actions[bot] so the auto-publish workflow keeps working).
This commit is contained in:
1 parent
786cbd496a
commit
fe15ae5243
2 files changed
+14
-8
No files matched your search
+5
-3
@@ -19,11 +19,13 @@
|
|||||||
# - restrict who can push directly to main (org admins only)
|
# - restrict who can push directly to main (org admins only)
|
||||||
|
|
||||||
# ---- Signing infrastructure (highest sensitivity) ----
|
# ---- Signing infrastructure (highest sensitivity) ----
|
||||||
/scripts/sign-plugins-index.mjs @suzukaze-haduki
|
# Anything that influences the bytes that get signed, OR the signing
|
||||||
/scripts/build-plugins-index.mjs @suzukaze-haduki
|
# step itself, requires owner approval. Build-script edits change the
|
||||||
/scripts/build-registry-index.mjs @suzukaze-haduki
|
# bytes that get signed even though they don't touch the sign step.
|
||||||
|
/scripts/ @suzukaze-haduki
|
||||||
/.github/workflows/ @suzukaze-haduki
|
/.github/workflows/ @suzukaze-haduki
|
||||||
/.github/CODEOWNERS @suzukaze-haduki
|
/.github/CODEOWNERS @suzukaze-haduki
|
||||||
|
/wrangler.toml @suzukaze-haduki
|
||||||
|
|
||||||
# ---- Auto-generated artefacts (must not be hand-edited) ----
|
# ---- Auto-generated artefacts (must not be hand-edited) ----
|
||||||
/plugins-index.json @suzukaze-haduki
|
/plugins-index.json @suzukaze-haduki
|
||||||
|
|||||||
@@ -83,11 +83,15 @@ jobs:
|
|||||||
REGISTRY_PRIVATE_KEY: ${{ secrets.REGISTRY_PRIVATE_KEY }}
|
REGISTRY_PRIVATE_KEY: ${{ secrets.REGISTRY_PRIVATE_KEY }}
|
||||||
run: node scripts/sign-plugins-index.mjs
|
run: node scripts/sign-plugins-index.mjs
|
||||||
|
|
||||||
# Defense in depth: verify the signature locally against the
|
# Defense in depth: verify the signature against the committed
|
||||||
# public key (committed in this repo as REGISTRY_PUBLIC_KEY env)
|
# pubkey before the .sig hits main. This catches an *accidental*
|
||||||
# before the .sig hits main. Catches a buggy or tampered
|
# sign-script regression — a malformed signature, an env-leak that
|
||||||
# sign-script run; closes PR re-review on the in-repo signing
|
# produces zero bytes, an off-by-one in the JSON canonicalization.
|
||||||
# path. No secret material here.
|
# It does NOT defend against an adversary, because an attacker
|
||||||
|
# who can edit sign-plugins-index.mjs in a PR can edit this verify
|
||||||
|
# step and the embedded pubkey in the same diff. The CODEOWNERS
|
||||||
|
# gate on `/scripts/` and `/.github/workflows/` is what stops
|
||||||
|
# adversarial edits, not this step.
|
||||||
- name: Verify signature against committed pubkey
|
- name: Verify signature against committed pubkey
|
||||||
env:
|
env:
|
||||||
REGISTRY_PUBLIC_KEY: ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
|
REGISTRY_PUBLIC_KEY: ClGa0Ucap8NdrKAy1rw9Tt6A9I8eg4zJ53+xIuKMuq0=
|
||||||
|
|||||||
Reference in new issue
Block a user