Repository navigation
Prepare signed release inventories and verify installation inputs - #308
Merged
Merged
Conversation
ctfbruce
marked this pull request as ready for review
September 28, 2026 11:20
Member
|
Deferring pending the package and CI foundations. The signed-release preparation work is valuable; please rebase onto current main and submit only its release-signing commits. |
Member
|
Keeping this deferred. Its prerequisites are now merged, and the release-signing commit rebases onto current main with two small conflicts in |
ctfbruce
marked this pull request as draft
October 2, 2026 07:34
ctfbruce
changed the base branch from
main
to
feat/measurement-workflows-and-limits
October 2, 2026 07:34
ctfbruce
force-pushed
the
feat/verified-release-bundles
branch
from
October 2, 2026 07:34
01e3331 to
70b0fbe
Compare
ctfbruce
changed the base branch from
feat/measurement-workflows-and-limits
to
main
October 2, 2026 11:26
ctfbruce
marked this pull request as ready for review
October 2, 2026 11:40
This was referenced Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Prepare signed release bundles that bind installers, all four component archives, compatibility metadata, checksums, source/build identities, CycloneDX inventory and provenance. Signed installation verifies the selected files with independently provisioned OpenSSH trust before execution. The existing checksum-only installation command remains usable while signing is unprovisioned and prints a warning; either trust setting or
DEBUGLET_REQUIRE_SIGNATURE=1requires complete trust and successful signature verification, with no fallback. Explicit unsigned mode cannot override configured trust or a signature requirement. Related to #137, #138, #139 and #140.The manually dispatched workflow consumes packages from successful CI on an exact protected version tag. It requires all 16 current CI checks, verifies independent approval protection for the signing environment, and keeps signing in a separate job that checks out no source and executes no candidate payload. The compatibility record is bound to the package source, version and OpenAPI digest. First-tag secret scans include the reachable history instead of silently selecting a one-commit range.
The integration prerequisite #354 is merged and this PR now targets
main. #322 adds retained evidence and private archive promotion separately.Validation: 56 focused release, inventory, bootstrap, CI and scanner checks pass on Aspire. Independent source review found no issues. All 16 checks pass in CI 36980153683 on
ea1aaaa39034756e8c7563d061264c3157abe1d4. The current package inventory/provenance logic was also checked against the actual 14-file CI package, including the compatibility sidecar. The bootstrap compatibility revision additionally passes all 19 focused tests; its fresh full CI run is 37001062695 ona81463c3289d50739456a6c94ea95ab051579be7.The first full-history scan surfaced two previously retired localhost TLS fixtures. Their existing removal record establishes that the disabled local configs gave them no runtime authority; two exceptions bind only to the original commit, exact path, rule and line. The real full-history scan then passed, with current files and future commits still covered.
No release, signing key, trust anchor or repository setting is activated here. Actual protected version tags, an independently reviewed signing environment, operator trust distribution and real release acceptance remain required. A signed Actions artifact alone does not establish durable retention; #141 remains open. Runtime base-image pins are not a complete OS package inventory, and BPF regeneration metadata does not establish the historical compiler for inherited objects.