Retain signed release evidence and audit private release archives - #322
Merged
Merged
Conversation
ctfbruce
force-pushed
the
feat/verified-release-bundles
branch
from
October 2, 2026 07:34
01e3331 to
70b0fbe
Compare
ctfbruce
force-pushed
the
feat/release-evidence-archive
branch
3 times, most recently
from
October 2, 2026 11:35
f3523f4 to
c49fb9d
Compare
Collect exact-attempt acceptance artifacts into the signed bundle, verify explicit private archive promotion, and audit pinned current and rollback releases without deletion or automatic policy changes. GitHub issue #141.
ctfbruce
force-pushed
the
feat/release-evidence-archive
branch
from
October 2, 2026 11:46
c49fb9d to
7824b1a
Compare
ctfbruce
marked this pull request as ready for review
October 2, 2026 11:56
This was referenced Oct 5, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Retain the exact source/run/attempt acceptance ZIPs and their digest index in each signed release bundle. Preparation rejects missing, expired or inconsistent evidence, including the runtime-image vulnerability check.
Provide explicit promotion to a configured private GitHub release archive: verify the signed input, upload a draft without replacing assets, independently download and verify it, then publish and confirm immutable release and asset identities. An audit reads an exact protected policy revision naming current and rollback versions, reporting source revisions, digests and missing items. Promotion does not change supported-version pointers, delete releases or prune assets.
Related to #141. The prerequisites #308 and #354 have merged; this PR now targets
main. The six-file retention change is unchanged, rebased onto merged main including the installation-compatibility correction.Validation: all 70 focused release, inventory, retention, bootstrap, CI and scanner checks pass on Aspire. Independent source review found no issues. All 16 checks pass in CI 36980156458 on
f3523f4f1af4e05cd47cdbfe5033d39ce8e25dde. The current candidate is7824b1ab557f012cb9837a96aa72828191309e4b; its final integration gate is CI 37002888320. Local fixtures cover missing evidence, interrupted uploads, conflicting releases, immutable publication identity and current/rollback audits; they do not establish actual GitHub archive activation.Actual private archive provisioning, protected signing activation, publish/download/access-control checks, and verified retrieval after source artifacts expire remain outstanding. #141 stays open until those acceptance conditions are met. No production deployment, signing setup or release publication occurs in this PR.