Skip to content

Harden pre-release developer and qualification paths - #21

Merged
jeremydixon22 merged 1 commit into
mainfrom
chore/oss-launch-hardening
Aug 11, 2026
Merged

Harden pre-release developer and qualification paths#21
jeremydixon22 merged 1 commit into
mainfrom
chore/oss-launch-hardening

Conversation

@jeremydixon22

Copy link
Copy Markdown
Member

Summary

  • Make the source checkout truthful and install-free: ./scripts/vyral run now executes generated apps, and CI proves citations, durable admission, restart recovery, replay, inspection, and reset under an isolated interpreter.
  • Add an executable source-native-to-indexed retrieval migration and refresh the retained ripgrep comparison from an enduring public-main ancestor.
  • Record an exact, explicitly unauthorized first package cohort and extend the GitHub control audit to rulesets and squash-only history.
  • Add a manual, short-lived AWS OIDC qualification path that emits only redacted S3/DynamoDB/SQS evidence and never promotes adapter maturity automatically.

Verification

  • Relevant unit and conformance tests pass.
  • Public API, contract, and maturity documentation is updated when applicable.
  • Provider-specific behavior has an opt-in live gate and does not widen a portable claim.
  • No credentials, customer data, local paths, generated artifacts, or deployment identities are included.
  • Release artifacts and public export were rehearsed when a package, client, container, or workflow changed.

./scripts/verify-release-artifacts.sh passed. The Python runtime completed 228 tests with mypy clean and verified wheel/sdist installs. The redacted local AWS gate passed through the existing least-privilege assumed role with S3, DynamoDB, SQS, and cleanup all successful.

Public information review

Does this change expose new public information? Yes

Publication is intentional for the user-facing migration walkthrough, refreshed benchmark evidence, proposed build-only package cohort, and the redacted AWS qualification contract. The cohort remains explicitly unauthorized, raw provider logs and identities stay private, and no internal planning material is included.

Compatibility and operations

The new vyral run PATH command is additive and fixes the documented zero-install source path. Publication remains disabled. The hosted AWS workflow will remain unable to authenticate until an AWS administrator adds the exact immutable GitHub environment subject to the existing least-privilege role trust; local assumed-role qualification is already passing.

@jeremydixon22
jeremydixon22 merged commit 2660bcb into main Aug 11, 2026
9 checks passed
@jeremydixon22
jeremydixon22 deleted the chore/oss-launch-hardening branch August 11, 2026 10:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant