Skip to content

ci: fail when a tracked image or PDF carries an asset manifest - #14

Merged
Bugs5382 merged 1 commit into
mainfrom
chore/20-asset-metadata-check
Oct 6, 2026
Merged

Bugs5382 merged 1 commit into
mainfrom
chore/20-asset-metadata-check

Conversation

@Bugs5382

@Bugs5382 Bugs5382 commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

What and why

Design-tool exports can embed a C2PA manifest, a JUMBF box, or a PNG caBX
chunk in an image or PDF, naming the tool that made the file, which counts
as attribution. A pre-push hook already blocks this locally, but it does
not cover a push from outside that one machine. This adds a caller job for
the new CryptOS-PKI/.github reusable asset-metadata check, so CI
enforces the same rule.

This repo's main branch was checked and has no tracked image or PDF that
carries the pattern, so the check starts clean.

Refs CryptOS-PKI/.github#20

Verification

  • Lint clean
  • Tests pass
  • Build succeeds
  • Documentation updated (if behavior or API changed)

How this was verified

actionlint on the new workflow file. The reusable workflow it calls was
proven end to end on a throwaway branch in CryptOS-PKI/.github (merged in
#21): a real GitHub Actions run passed on a clean checkout, and the
detection logic was verified locally against the pre-push hook's own
C2PA/caBX fixtures. No source change here beyond the caller job, so no
tests, build, or docs are affected.

Calls the CryptOS-PKI/.github reusable check so CI enforces what the
local pre-push hook already blocks.

Signed-off-by: Bugs5382 <12115015+Bugs5382@users.noreply.github.com>
@Bugs5382 Bugs5382 self-assigned this Oct 6, 2026
@Bugs5382
Bugs5382 marked this pull request as ready for review October 6, 2026 20:27
@Bugs5382
Bugs5382 merged commit 91ffbf7 into main Oct 6, 2026
2 checks passed
@Bugs5382
Bugs5382 deleted the chore/20-asset-metadata-check branch October 6, 2026 20:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant