Expand description
The provider catalogue: a signed, public table of issuer key prefixes that
unv enrich consults before the table compiled into the binary.
The compiled table can only be updated by a release. This one is published as a static file, fetched whole (a per-provider request would tell the host which providers you hold credentials for), cached locally and verified on every load, not only on download.
Enrichment writes into the vault, so a tampered catalogue could mislabel secret types or point a card at an attacker’s URL. Hence:
- an Ed25519 signature over the exact payload bytes, checked against
PINNED_KEY_HEX, which lives in the binary; generated_atmay never go backwards (replaying an old, valid file);- every field is shape-checked after the signature, because a correctly
signed typo is still a typo: prefixes under 3 characters would match
nearly every secret, and non-
httpsURLs never reach a card.
The catalogue holds no secrets and no user data. See ADR-0139.
Structs§
Constants§
- DEFAULT_
URL - Where the scheduled
docs.ymlrun publishes the signed catalogue. Not yet verified against a live Pages deployment. - PINNED_
KEY_ HEX - Ed25519 public key the catalogue must be signed with. The private half is
the
CATALOGUE_SIGNING_KEYActions secret; rotating it means a release. - SCHEMA
Functions§
- cache_
path - load_
cached - The cached catalogue, re-verified now. A bad or missing file is
None, so enrichment falls back to the compiled table instead of failing. - sign
- Publisher side: sign
cwith a 32-byte Ed25519 seed. Used byunv catalogue signin the scheduled workflow. - store
- Verify
rawagainst the pinned key, refuse a rollback, and cache it atomically (0600). Returns the accepted catalogue. - verify
- Check signature and shape. Does not look at the cache.