SkillByAIOpen interactive version →

Lesson 15 / 25

Protected Paths and File Allowlists

Some files are never in scope.

Deny by path

Define paths an automated fixer may never modify: CI workflows, infrastructure code, database migrations, lock files, secrets and configuration, tests, and security-sensitive modules. Enforce it in the pipeline (reject patches touching them) and in repository settings (CODEOWNERS requiring specific reviewers, branch protection). An allowlist of directories the fixer may edit is even stronger for narrow use cases.

A protected-path gate, run

I ran this with Python 3 (standard library) and, where it uses git, real git in a throwaway temporary repository. Candidate patches are written by hand to stand in for model output. A patch touching only src/pricing.py is allowed. Patches that also touch tests, a CI workflow or poetry.lock are blocked, and the offending file is named.

from fnmatch import fnmatch
PROTECTED = [".github/workflows/*", "migrations/*", "*.lock", "infra/*", "secrets/*", "tests/*"]
def gate(files):
    hits = [f for f in files if any(fnmatch(f, p) for p in PROTECTED)]
    return ("BLOCK", hits) if hits else ("ALLOW", [])
for files in [["src/pricing.py"],
              ["src/pricing.py", "tests/test_pricing.py"],
              ["src/pricing.py", ".github/workflows/ci.yml"],
              ["poetry.lock", "src/db.py"]]:
    print(files, "->", *gate(files))

Output:

['src/pricing.py'] -> ALLOW []
['src/pricing.py', 'tests/test_pricing.py'] -> BLOCK ['tests/test_pricing.py']
['src/pricing.py', '.github/workflows/ci.yml'] -> BLOCK ['.github/workflows/ci.yml']
['poetry.lock', 'src/db.py'] -> BLOCK ['poetry.lock']

Back it with CODEOWNERS

Require named owners to approve changes to sensitive paths, so even a pipeline bug cannot slip them through.

Quick check: Why protect CI workflow files from automated fixes?

  • Editing CI can disable the very checks that verify the fix
  • They are too small to edit
  • Git cannot track them
  • They contain only comments
Answer

Editing CI can disable the very checks that verify the fix — The fixer must not change its own judge.