Skip to content

feat: add secure-runtime snapshot comparator - #307

Open
shaggitza wants to merge 4 commits into
mainfrom
feat/100-secure-runtime-benchmark
Open

feat: add secure-runtime snapshot comparator#307
shaggitza wants to merge 4 commits into
mainfrom
feat/100-secure-runtime-benchmark

Conversation

@shaggitza

Copy link
Copy Markdown
Owner

Summary

  • add a schema-v1 comparator for paired secure-AST and isolated-runtime list/impact snapshots
  • validate exact configuration, provenance, inventory, impact, telemetry, resource, image, lock, SBOM, and snapshot bindings before comparison
  • separate operational outcomes from the paired-success quality subset and preserve runtime as a positive-observation comparator—not truth
  • require source adjudication for every disagreement and retain canonical provenance digests

Scope and closed gates

This is the comparator foundation for #100. It does not implement or authorize a real artifact producer, execute a corpus, run a trusted runtime, or publish canonical results.

The producer gate and trusted gVisor/Kata canary gate remain CLOSED. Snapshot-specific pinned images/SBOMs and trusted list/analyze canaries are still required before any execution or publication.

Validation

Advances #100

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants