Skip to content

[PLUGINS] Add deterministic plugin checksum/signature verification in CI #230

Description

@utksh1

Problem

SecuScan needs a production-grade improvement in this area: Plugin integrity automation..

Scope

Fail CI when plugin metadata checksum/signature is stale, provide a focused error message, and document the refresh/sign commands.

Acceptance Criteria

  • The implementation is focused and does not introduce unrelated UI, docs, lockfile, or formatting churn.
  • Security-sensitive behavior has explicit negative tests where applicable.
  • Existing tests continue to pass, and new tests cover the main success and failure paths.
  • Documentation or configuration examples are updated when operator behavior changes.

Verification

CI tests should fail on a deliberately modified plugin fixture and pass after refresh.

Difficulty

Hard, useful issue intended for experienced contributors.

Metadata

Metadata

Assignees

Labels

area:ciCI, tooling, or automation workarea:pluginsScanner plugin metadata, schemas, or plugin runtime workarea:securitySecurity-sensitive implementation or testslevel:advanced55 pts difficulty label for advanced contributor PRspriority:highHigh-priority issuetype:devopsDevOps or infrastructure work category bonus labeltype:securitySecurity work category bonus label

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions