Add observed-effect references integration - #246
astrogilda wants to merge 3 commits into
Conversation
Five signed TRACE Trust Records cite observer-signed in-toto statements through a references entry with rel observed-effect. The tests verify each record with released agentrust-trace and recompute the relying-party verdict from the committed bytes; CI also replays the published vectors-observed-effect corpus at v0.15.0. Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com>
|
🔴 Contributor Check: HIGH
Automated check by AgenTrust Contributor Check. |
|
@imran-siddique -- trace-spec#403 is merged and its merge checks are green. This integration makes the accepted examples runnable against the pinned Probity corpus. The remaining blocker is corpus installation on Python 3.11/3.12. I'd like this to become a recurring CI check for the observed-effect relation once that is resolved. |
|
@astrogilda the corpus step fails on 3.11 and 3.12 because every |
Signed-off-by: Sankalp Gilda <sankalp.gilda@gmail.com>
|
@astrogilda running the replay under its own 3.13 on every leg is better than gating it: 3.11 and 3.12 now get the replay too, and all eight jobs pass. One mechanical step left: |
|
I merged current main and regenerated marketplace/catalog.json at fff10d6. GitHub is now holding the refreshed workflows for maintainer approval. Could you approve them? Once Validate integrations is green, this satisfies the final condition you set for the community-tier merge. |
This adds integrations/probityai-observed-effect, the integration @imran-siddique asked about on agentrust-io/awesome-ai-governance#108.
Five signed TRACE Trust Records each carry a references entry with rel observed-effect, pointing at an in-toto statement that an observer outside the agent signed. I copied the two observer statements those records cite byte for byte from vectors-observed-effect at v0.15.0. The tests verify every record with released agentrust-trace 0.11.0. They also recompute each relying-party verdict from the committed bytes: verified, digest mismatch, unresolved, and observer key not configured.
To reproduce for the Verified tier:
trace-spec#403 proposes the observed-effect value and the registry does not list it yet, so I claim no conformance level.