Skip to content

fix: publish only approved workflow catalog entries - #36

Merged
vitormattos merged 5 commits into
mainfrom
fix/catalog-publish-allowlist
Sep 20, 2026
Merged

vitormattos merged 5 commits into
mainfrom
fix/catalog-publish-allowlist

Conversation

@vitormattos

Copy link
Copy Markdown
Member

Summary

Make catalog publication explicitly opt-in instead of treating every file under workflow-templates/ as automatically publishable.

Why

The first real GitHub App publication run correctly opened LibreCodeCoop/.github#21, but that PR exposed appstore-build-publish.yml even though the release/publication workflow family has not yet completed the same security and consumer validation process as the lint/build workflows.

Changes

  • add workflow-catalog.json as the catalog allowlist;
  • initially approve only the 10 templates already validated in LibreCodeCoop/extract;
  • make sync_catalog.py publish only manifest-listed templates;
  • validate every declared template/metadata pair;
  • preserve support for custom SVG icons;
  • remove stale catalog entries that are no longer approved;
  • add regression tests proving unapproved templates are neither added nor retained.

appstore-build-publish remains generated in this repository, but will not be exposed through Actions → New workflow until its sensitive release path is explicitly reviewed and approved.

@vitormattos
vitormattos merged commit 0841254 into main Sep 20, 2026
4 of 5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant