mirror of
https://github.com/mvanhorn/cli-printing-press.git
synced 2026-09-14 15:38:08 +08:00
chore(ci): add CODEOWNERS for workflows and CODEOWNERS itself (#1472)
* chore(ci): add CODEOWNERS to gate edits to workflows and CODEOWNERS itself Defense in depth alongside the org-level "Approve fork PR workflows for first-time contributors who are new to GitHub" setting. Workflow files have access to repo secrets at runtime; CODEOWNERS controls who can edit the gating rules themselves. Both must require an explicit maintainer review before merging. Lists @tmchow and @mvanhorn so bus factor is 2 and a single absence doesn't block workflow changes. * chore(ci): extend CODEOWNERS to scripts/ and .github/scripts/ Greptile P1 flagged the gap: workflows run `bash .github/scripts/validate-skill-docs.sh` and `scripts/golden.sh verify` in steps that have secrets in scope, so an edit to either script directory has the same exfiltration potential as editing the workflow YAML. Add both to the gate.
This commit is contained in:
@@ -0,0 +1,14 @@
|
||||
# Code owners for security-sensitive paths.
|
||||
# A malicious PR that modifies these paths could exfiltrate secrets at workflow
|
||||
# runtime or weaken the merge-gate; require an explicit maintainer review.
|
||||
# See: docs.github.com/en/repositories/managing-your-repositorys-settings-and-security/customizing-your-repository/about-code-owners
|
||||
#
|
||||
# Coverage rationale: anything a workflow can `run:` is effectively part of
|
||||
# the workflow's trust boundary. That includes workflow YAML, scripts checked
|
||||
# into the repo that workflows invoke, and CODEOWNERS itself (so a malicious
|
||||
# PR cannot strip the gate before exploiting it).
|
||||
|
||||
.github/workflows/ @tmchow @mvanhorn
|
||||
.github/scripts/ @tmchow @mvanhorn
|
||||
scripts/ @tmchow @mvanhorn
|
||||
.github/CODEOWNERS @tmchow @mvanhorn
|
||||
Reference in New Issue
Block a user