Repository navigation
Security: Add artifact access control and protection policy - #4
sparkainlp-x with Copilot wants to merge 1 commit into
Conversation
Co-authored-by: sparkainlp-x <281253927+sparkainlp-x@users.noreply.github.com>
|
Reviewed — not merging as-is:
A shorter SECURITY.md with only the private vulnerability-reporting process (GitHub private advisories) and accurate artifact guidance would be welcome as a new docs-only PR. |
|
Thank you for this draft. Rather than keeping a repo-specific policy, the security policy is now defined account-wide in sparkainlp-x/.github/SECURITY.md (merged in sparkainlp-x/.github#1), and GitHub private vulnerability reporting is enabled on this repository (Security tab → Report a vulnerability). That default applies here automatically, so I'm closing this PR as superseded. The artifact-retention points in this draft are covered in the new policy's Build artifacts section. If anything specific to this repo is still missing, please open an issue. |
|
One more note for the record: on a public repository, GitHub Actions artifacts can be downloaded by any signed-in GitHub user, so the "restricted to authorized users" wording in this draft would not have been accurate. The account-wide policy therefore only states that hardware artifacts are not published in the repository and are kept for a limited retention period. If bitstreams ever need real access control, the hardware job should upload to private storage instead of Actions artifacts. |
Summary
This PR adds comprehensive security protections for sensitive hardware artifacts (bitstream, bootloader, PetaLinux images) and implements access control mechanisms in GitHub Actions.
Changes Made
1. GitHub Actions Workflow Security (
.github/workflows/ci.yml)actions: read(artifact access only for authorized users)(RESTRICTED - Authorized Users Only)workflow_dispatchmanual triggerself-hosted,vivado,zcu111)2. Security Policy Documentation (
SECURITY.md- NEW)download.bit,BOOT.BIN,image.ub,*.xsa3. Documentation Update (
README.md)SECURITY.mdin the hardware CI sectionSecurity Model
mainNext Steps (Manual Configuration on GitHub UI)
To complete the protection, enable branch protections:
mainbranch with:Related Issues
N/A (proactive security hardening)
Breaking Changes
None - all changes are additive and maintain backward compatibility.
Testing
No tests required - documentation and configuration changes only. Existing CI pipeline unchanged.