Security
Your code, CI and publishing access stay under your control.
ExtensionOps is designed to inspect and coordinate releases without becoming the place where your extension code or publishing identity has to live.
Public scans do not run repository code
Public-repository analysis is static. ExtensionOps reads the files needed for release checks without executing the repository.
Private repository access is scoped
When you connect GitHub, you choose which repositories the ExtensionOps GitHub App can access.
Builds and browser checks stay in GitHub
Validation workflows run on GitHub-hosted or customer-controlled runners rather than on ExtensionOps infrastructure.
Publishing credentials stay with you
Chrome Web Store publishing identity and credentials remain in your GitHub and Google Cloud environment.
Changes remain reviewable
Findings and fixes are presented with evidence. Automatic release actions require explicit customer opt-in.
Release evidence is traceable
Findings can be tied to the relevant rule, source file, patch and validation result so release decisions are easier to audit.