What: - add flake.lock GitHub owner allowlist + check script - run allowlist check in config-options CI Why: - guard against unexpected supply-chain inputs Tests: - scripts/check-flake-lock-owners.sh flake.lock scripts/allowed-flake-lock-owners.txt |
||
|---|---|---|
| .. | ||
| allowed-flake-lock-owners.txt | ||
| check-flake-lock-owners.sh | ||
| update-pins.sh | ||