Skip to content

fix: decode Runtime DSSE provenance for v0.1.9 - #14

Merged
hututuQQQ merged 2 commits into
mainfrom
codex/release-v0.1.9
Aug 6, 2026
Merged

hututuQQQ merged 2 commits into
mainfrom
codex/release-v0.1.9

Conversation

@hututuQQQ

Copy link
Copy Markdown
Owner

Summary

  • decode the production Runtime provenance as a bounded canonical DSSE envelope instead of treating it as a raw SLSA statement
  • require valid UTF-8, the in-toto/SLSA types, and Sigma's portable Runtime build type before matching version/platform/architecture
  • add coverage that accepts the production envelope contract and rejects raw statements
  • bump coordinated Sigma Code desktop metadata to 0.1.9; immutable failed publication tags are not moved

Validation

  • focused desktop/release Vitest: 37 passed
  • real locally generated Runtime DSSE envelope accepted and bound to win32-x64
  • pnpm build:desktop
  • pnpm typecheck
  • pnpm lint
  • retained integrated app snapshot reports codex/release-v0.1.9

@github-actions github-actions Bot added size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. labels Aug 6, 2026
@hututuQQQ
hututuQQQ merged commit a44e6e0 into main Aug 6, 2026
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M vouch:trusted PR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant