Lesson 11 / 25
Protected Paths
Require approval before the agent edits CI, infrastructure, secrets and dependency files.
Some files matter more
Not every file is equal. A change to .github/workflows/*, infrastructure code, deployment config, .env*, private keys or dependency lockfiles can affect production or leak access far beyond what a typo fix deserves. List these as protected paths: edits are blocked or need explicit approval, and a diff that touches them is flagged in review.
Matching protected paths, run
I ran this with Python's fnmatch. The workflow file and .env.local are flagged; ordinary source and docs are not.
import fnmatch
PROTECTED = [".github/workflows/*", "infra/*", "*.pem", ".env*", "package-lock.json"]
def touches_protected(paths):
return [p for p in paths if any(fnmatch.fnmatch(p, g) for g in PROTECTED)]
print(touches_protected(["src/app.py", ".github/workflows/deploy.yml", ".env.local", "README.md"]))
Output:
['.github/workflows/deploy.yml', '.env.local']
Back it with CODEOWNERS
On GitHub, a CODEOWNERS file plus branch protection requires a named reviewer for changes to sensitive paths. That enforces the same rule on humans and agents even if the local tool policy is bypassed.
Quick check: Which file should usually be a protected path?
- A unit test for a helper
- A README paragraph
- A code comment
- A CI workflow file
Answer
A CI workflow file — CI files control what runs with repository secrets, so changes need extra scrutiny.