Skip to content

Retain signed release evidence and audit private release archives - #322

Merged
ctfbruce merged 1 commit into
mainfrom
feat/release-evidence-archive
Oct 2, 2026
Merged

ctfbruce merged 1 commit into
mainfrom
feat/release-evidence-archive

Conversation

@ctfbruce

@ctfbruce ctfbruce commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Retain the exact source/run/attempt acceptance ZIPs and their digest index in each signed release bundle. Preparation rejects missing, expired or inconsistent evidence, including the runtime-image vulnerability check.

Provide explicit promotion to a configured private GitHub release archive: verify the signed input, upload a draft without replacing assets, independently download and verify it, then publish and confirm immutable release and asset identities. An audit reads an exact protected policy revision naming current and rollback versions, reporting source revisions, digests and missing items. Promotion does not change supported-version pointers, delete releases or prune assets.

Related to #141. The prerequisites #308 and #354 have merged; this PR now targets main. The six-file retention change is unchanged, rebased onto merged main including the installation-compatibility correction.

Validation: all 70 focused release, inventory, retention, bootstrap, CI and scanner checks pass on Aspire. Independent source review found no issues. All 16 checks pass in CI 36980156458 on f3523f4f1af4e05cd47cdbfe5033d39ce8e25dde. The current candidate is 7824b1ab557f012cb9837a96aa72828191309e4b; its final integration gate is CI 37002888320. Local fixtures cover missing evidence, interrupted uploads, conflicting releases, immutable publication identity and current/rollback audits; they do not establish actual GitHub archive activation.

Actual private archive provisioning, protected signing activation, publish/download/access-control checks, and verified retrieval after source artifacts expire remain outstanding. #141 stays open until those acceptance conditions are met. No production deployment, signing setup or release publication occurs in this PR.

@ctfbruce
ctfbruce force-pushed the feat/verified-release-bundles branch from 01e3331 to 70b0fbe Compare October 2, 2026 07:34
@ctfbruce
ctfbruce force-pushed the feat/release-evidence-archive branch 3 times, most recently from f3523f4 to c49fb9d Compare October 2, 2026 11:35
@ctfbruce
ctfbruce changed the base branch from feat/verified-release-bundles to main October 2, 2026 11:42
Collect exact-attempt acceptance artifacts into the signed bundle, verify explicit private archive promotion, and audit pinned current and rollback releases without deletion or automatic policy changes.

GitHub issue #141.
@ctfbruce
ctfbruce force-pushed the feat/release-evidence-archive branch from c49fb9d to 7824b1a Compare October 2, 2026 11:46
@ctfbruce
ctfbruce marked this pull request as ready for review October 2, 2026 11:56
@ctfbruce
ctfbruce merged commit 03f5511 into main Oct 2, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant