ci: attest release artifacts before publication - #151
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Superseded by current-protected-main Draft #154, reconstructed from protected Convergence proof: #151 and #154 change the same nine repository paths, and all nine #154 blobs match #151 byte-for-byte: #151 remains non-mergeable on stale base snapshot |
Purpose
Clean current-main replacement for stale stacked PR #138. Make buyer-verifiable release provenance and exact release-version admission first-class release gates without carrying #137 ancestry or overlapping #147's Test/coverage workflow ownership.
Test-first state
Exact base at branch creation:
4b2f5d30c1f1961e017a84aa1c785d3f1b1bb9af.Initial RED head:
1700a3d438c89abca4309331a1f4a17520080c92.The RED requires a cross-platform release-version verifier and packaging hook that protected main does not yet implement. Subsequent commits will reconstruct only the release-owned workflow, admission tests, executable verifier, doctoring, and changelog from current main.
.github/workflows/test.ymland generic coverage configuration remain owned by #147 and are intentionally excluded to avoid duplicated control-plane edits.Intended authority boundary
contents: read,id-token: write, andattestations: writebut no publication authority;contents: writeonly after successful attestation;Keep Draft until production implementation, deterministic tests, current-head Release/Test/security/SAST, exact coverage integration, review findings, and live repository policy are satisfied.