chore: never let publisher signing seeds into git - #1
Conversation
pluginsign reads a raw 32-byte Ed25519 seed from a file path. Nothing is committed today, but the only thing between a publisher seed and main was one `git add -A` — so ignore key material outright rather than relying on care.
|
[ack] — zeus review, Olympus TASK-0007 seeds batch (2026-07-26): preventive guard verified — I independently re-scanned all-refs history ( |
|
The reviewed seed-guard change is now landed on |
pluginsignreads a raw 32-byte Ed25519 publisher seed from a file path (-seed seed.bin). No.gitignorein this repo excluded*.key,*.pem,seed*, or*.bin.Nothing is committed today — I scanned every tracked file and the full history (
--diff-filter=Aacross all refs) in all seven Lattice repos and found no key material. So this is preventive: the only thing standing between a publisher seed andmainwas onegit add -A.A leaked publisher seed lets an attacker sign a plugin manifest that the server will load as trusted, so the blast radius is the whole plugin trust model. Cheap guard, high value.
Found during the 2026-07-14 plugin-boundary architecture review (§4.8).
https://claude.ai/code/session_01FzYExyy6G7Cb7QpXoUEY78