You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Noema provides an evidence-producing quarantine plane for untrusted repository patches/code/files without exposing reviewer/model/GitHub-write/NVIDIA NIM/OIDC/release/deployment or host-Docker authority to the analyzed workload. Callers receive exact source/patch/runtime/result provenance rather than arbitrary shell authority.
Protected truth — 2026-08-25
Current protected main is GitHub-verified 2c83355529447248c246805d1954f268e027d2ab. The dedicated patch-validator image/runtime/supply-chain slice entered protected history through #407 as squash commit 8ce7c7536888ec0b596e18368eedd9379deec64f and remains present on the current protected lineage. The older #407 integration SHA is historical integration evidence, not the current protected tip.
Phase A — exact-source quarantine: protected
Protected source preserves exact repository/base/head/patch/profile binding; allowlisted validation profiles; strict patch path/mode/hunk/file-count/governance-path validation; exact Git/worktree/tree/object identity; archive/materialized-file parity; descriptor-safe/no-follow/size-bounded reads; bounded no-network/read-only/non-root isolation without Docker socket or privileged credentials; and trusted-host result validation.
Phase B — dedicated validator image: protected
#407 exact head 871490009a65336003047a85b994581ed3e36b44 reached terminal success in Application CI 32619804074, reviewer-ci 32619804030, central Security Scan 32619804069, and dedicated patch-validator-image32619804032, with zero unresolved review findings, before squash integration as protected commit 8ce7c7536888ec0b596e18368eedd9379deec64f.
Protected source on current main@2c833555... still includes the fully-static scratch runtime, no-network/read-only/numeric-non-root smoke, exact source/image/receipt binding, Trivy/Syft/Grype/CycloneDX/SBOM evidence, pinned scanners, reviewed bundled-runtime identities/provenance/applicability, fail-closed vulnerability thresholds, exact Noema smoke-repository binding and receipt-path identity stability.
Historical predecessor #67 was semantically compared against the integrated successor and closed as superseded without merge. #66 owns protected-main operational image acceptance plus later immutable publication/signing/attestation/activation.
No GitHub release currently exists for Noema. Historical PR-head image evidence does not substitute for protected-main operational acceptance or an immutable published artifact.
Acceptance criteria
Exact-source quarantine
Exact-source patch quarantine is protected on current main.
Preserve credential-free typed validation profiles and exact source/patch/result evidence binding.
Re-run protected-main operational acceptance when this boundary is included in an immutable release candidate; retain exact evidence rather than reusing historical PR checks.
Dedicated image
Reconstruct the image/runtime/verifier/reviewer integration on protected lineage.
Require exact static-runtime identity and required JavaScript capabilities.
Require real no-network/read-only/non-root smoke and exact source/image/receipt binding.
Bind SBOM, vulnerability and embedded-runtime inventories to exact image/source identity.
Repair builder/runtime/scanner evidence failures test-first without weakening image isolation or scanner threshold.
Buyer / product boundary
Noema provides an evidence-producing quarantine plane for untrusted repository patches/code/files without exposing reviewer/model/GitHub-write/NVIDIA NIM/OIDC/release/deployment or host-Docker authority to the analyzed workload. Callers receive exact source/patch/runtime/result provenance rather than arbitrary shell authority.
Protected truth — 2026-08-25
Current protected
mainis GitHub-verified2c83355529447248c246805d1954f268e027d2ab. The dedicated patch-validator image/runtime/supply-chain slice entered protected history through #407 as squash commit8ce7c7536888ec0b596e18368eedd9379deec64fand remains present on the current protected lineage. The older #407 integration SHA is historical integration evidence, not the current protected tip.Phase A — exact-source quarantine: protected
Protected source preserves exact repository/base/head/patch/profile binding; allowlisted validation profiles; strict patch path/mode/hunk/file-count/governance-path validation; exact Git/worktree/tree/object identity; archive/materialized-file parity; descriptor-safe/no-follow/size-bounded reads; bounded no-network/read-only/non-root isolation without Docker socket or privileged credentials; and trusted-host result validation.
Phase B — dedicated validator image: protected
#407 exact head
871490009a65336003047a85b994581ed3e36b44reached terminal success in Application CI32619804074, reviewer-ci32619804030, central Security Scan32619804069, and dedicatedpatch-validator-image32619804032, with zero unresolved review findings, before squash integration as protected commit8ce7c7536888ec0b596e18368eedd9379deec64f.Protected source on current
main@2c833555...still includes the fully-static scratch runtime, no-network/read-only/numeric-non-root smoke, exact source/image/receipt binding, Trivy/Syft/Grype/CycloneDX/SBOM evidence, pinned scanners, reviewed bundled-runtime identities/provenance/applicability, fail-closed vulnerability thresholds, exact Noema smoke-repository binding and receipt-path identity stability.Historical predecessor #67 was semantically compared against the integrated successor and closed as superseded without merge. #66 owns protected-main operational image acceptance plus later immutable publication/signing/attestation/activation.
No GitHub release currently exists for Noema. Historical PR-head image evidence does not substitute for protected-main operational acceptance or an immutable published artifact.
Acceptance criteria
Exact-source quarantine
main.Dedicated image
workflow_dispatchevidence path on the then-current protected revision.Extended graph/code/data capability
Guardrails
No arbitrary model-generated shell command, self-modifying/branch-patching workflow, Docker socket, host-writable final evidence directory, GitHub write/reviewer/model/NVIDIA NIM/OIDC/signing/publication/release/deployment credential exposure, invented outbound license, or claim that sandbox PASS itself is approval/merge/release/acquisition authority.
Related: #5, #27, #29, #66, #407.