Skip to main content

Module catalogue

Module catalogue 

Source
Expand description

The provider catalogue: a signed, public table of issuer key prefixes that unv enrich consults before the table compiled into the binary.

The compiled table can only be updated by a release. This one is published as a static file, fetched whole (a per-provider request would tell the host which providers you hold credentials for), cached locally and verified on every load, not only on download.

Enrichment writes into the vault, so a tampered catalogue could mislabel secret types or point a card at an attacker’s URL. Hence:

  • an Ed25519 signature over the exact payload bytes, checked against PINNED_KEY_HEX, which lives in the binary;
  • generated_at may never go backwards (replaying an old, valid file);
  • every field is shape-checked after the signature, because a correctly signed typo is still a typo: prefixes under 3 characters would match nearly every secret, and non-https URLs never reach a card.

The catalogue holds no secrets and no user data. See ADR-0139.

Structs§

Catalogue
Provider

Constants§

DEFAULT_URL
Where the scheduled docs.yml run publishes the signed catalogue. Not yet verified against a live Pages deployment.
PINNED_KEY_HEX
Ed25519 public key the catalogue must be signed with. The private half is the CATALOGUE_SIGNING_KEY Actions secret; rotating it means a release.
SCHEMA

Functions§

cache_path
load_cached
The cached catalogue, re-verified now. A bad or missing file is None, so enrichment falls back to the compiled table instead of failing.
sign
Publisher side: sign c with a 32-byte Ed25519 seed. Used by unv catalogue sign in the scheduled workflow.
store
Verify raw against the pinned key, refuse a rollback, and cache it atomically (0600). Returns the accepted catalogue.
verify
Check signature and shape. Does not look at the cache.