Round-3 PR re-review follow-ups: LOW — CODEOWNERS missed /scripts/build-plugins-index.mjs and /wrangler.toml. Both can change the bytes that get signed without touching the sign step. Replaced the per-file enumeration with /scripts/ catch-all and added wrangler.toml. HIGH — workflow comment said the post-sign verify step "catches a buggy or tampered sign-script run". The "tampered" claim was wrong: any attacker who can edit sign-plugins-index.mjs in a PR can edit the verify step (and the embedded pubkey) in the same diff. Re-stated as "catches accidental regressions only — CODEOWNERS is what stops adversarial edits". Branch protection on main has been enabled separately via gh API (force-push + deletion blocked, PR review required, CODEOWNERS enforced; bypass for repo owner and github-actions[bot] so the auto-publish workflow keeps working).
34 lines
1.6 KiB
Plaintext
34 lines
1.6 KiB
Plaintext
# CODEOWNERS for librefang-registry
|
|
#
|
|
# A push to main can trigger the registry-worker forced-refresh and have
|
|
# whatever's in plugins-index.json signed by the registry's Ed25519 key
|
|
# (REGISTRY_PRIVATE_KEY in this repo's GitHub Actions store). Branch
|
|
# protection alone doesn't constrain WHICH files a maintainer can land —
|
|
# CODEOWNERS does.
|
|
#
|
|
# Files listed here REQUIRE explicit approval from the listed owners
|
|
# before a PR can land. The signing infrastructure (workflow + script)
|
|
# and the artefacts it produces (committed indexes + signature) carry
|
|
# the highest sensitivity. Plugin contributions under plugins/<name>/
|
|
# are owned by the plugin author but still go through PR review.
|
|
#
|
|
# Branch protection on `main` MUST be configured to:
|
|
# - require pull request reviews (at least 1)
|
|
# - require review from CODEOWNERS
|
|
# - dismiss stale approvals on new commits
|
|
# - restrict who can push directly to main (org admins only)
|
|
|
|
# ---- Signing infrastructure (highest sensitivity) ----
|
|
# Anything that influences the bytes that get signed, OR the signing
|
|
# step itself, requires owner approval. Build-script edits change the
|
|
# bytes that get signed even though they don't touch the sign step.
|
|
/scripts/ @suzukaze-haduki
|
|
/.github/workflows/ @suzukaze-haduki
|
|
/.github/CODEOWNERS @suzukaze-haduki
|
|
/wrangler.toml @suzukaze-haduki
|
|
|
|
# ---- Auto-generated artefacts (must not be hand-edited) ----
|
|
/plugins-index.json @suzukaze-haduki
|
|
/plugins-index.json.sig @suzukaze-haduki
|
|
/registry-index.json @suzukaze-haduki
|