Lesson 11 / 25

Protected Paths

Require approval before the agent edits CI, infrastructure, secrets and dependency files.

Some files matter more

Not every file is equal. A change to .github/workflows/*, infrastructure code, deployment config, .env*, private keys or dependency lockfiles can affect production or leak access far beyond what a typo fix deserves. List these as protected paths: edits are blocked or need explicit approval, and a diff that touches them is flagged in review.

Matching protected paths, run

I ran this with Python's fnmatch. The workflow file and .env.local are flagged; ordinary source and docs are not.

import fnmatch
PROTECTED = [".github/workflows/*", "infra/*", "*.pem", ".env*", "package-lock.json"]

def touches_protected(paths):
    return [p for p in paths if any(fnmatch.fnmatch(p, g) for g in PROTECTED)]

print(touches_protected(["src/app.py", ".github/workflows/deploy.yml", ".env.local", "README.md"]))

Output:

['.github/workflows/deploy.yml', '.env.local']

Back it with CODEOWNERS

On GitHub, a CODEOWNERS file plus branch protection requires a named reviewer for changes to sensitive paths. That enforces the same rule on humans and agents even if the local tool policy is bypassed.

Quick check: Which file should usually be a protected path?

  • A unit test for a helper
  • A README paragraph
  • A code comment
  • A CI workflow file
Answer

A CI workflow file — CI files control what runs with repository secrets, so changes need extra scrutiny.