Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Signatures are written to files tracked by git #13

Open
maurelian opened this issue May 15, 2024 · 0 comments
Open

Signatures are written to files tracked by git #13

maurelian opened this issue May 15, 2024 · 0 comments

Comments

@maurelian
Copy link
Contributor

maurelian commented May 15, 2024

Description

The current approach to file manipulation creates a real risk of leaking signatures to github.

After running the merge command in the Presigner flow (instructions, justfile), the signatures are added to the both the draft-NN.json and ready-NN.json files.

The ready files are git-ignored in the superchain-ops .gitignore, but the draft files cannot be because they need to be included as preparation for the signing.

The draft files should not be updated by the merge command, as this makes it too easy to commit and push them, which would expose them publicly

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant