diff --git a/.github/release-body.md b/.github/release-body.md index ad5dfc9..5058c4f 100644 --- a/.github/release-body.md +++ b/.github/release-body.md @@ -33,7 +33,7 @@ gh attestation verify kaibo-${TAG}-x86_64-unknown-linux-musl.tar.gz -R tobert/ka gh attestation verify oci://ghcr.io/tobert/kaibo:${VERSION} -R tobert/kaibo ``` -Or keyless-verify the signed checksum manifest with cosign ≥ 3 (covers every file it lists, works offline): +Or keyless-verify the signed checksum manifest with cosign ≥ 2.5 (covers every file it lists, works offline): ```sh cosign verify-blob \ diff --git a/CHANGELOG.md b/CHANGELOG.md index 9c309e4..baa54cf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -103,8 +103,8 @@ record. Each later release appends a new section at the top. ### Fixed -- **The README's cosign floor said 3, and 2.5 verifies a release** — the old floor turned - away working installs. +- **The cosign floor said 3, and 2.5 verifies a release** — the old floor turned away + working installs, and the release page repeated it. - **The explorer's shell no longer drops piped or buffered stdin** across `read`/`grep`/`cat`, and a loop that exits early keeps what it already printed. diff --git a/docs/releases.md b/docs/releases.md index 30ef412..da89596 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -59,7 +59,7 @@ publish job, so a `workflow_dispatch` smoke run never mints an OIDC identity (bu keep `contents: read`; the publish job adds `id-token: write` + `attestations: write`). The layout, decided with Amy: **one signed aggregate `checksums.txt`** (cosign keyless — verify once, `sha256sum -c` covers any file it lists; one signature shape, the -self-contained `.sigstore.json` bundle, which verifies offline with cosign ≥ 3; the +self-contained `.sigstore.json` bundle, which verifies offline with cosign ≥ 2.5; the per-artifact `.sha256` sidecars stay for the README's download one-liner), **per-artifact SLSA provenance** via `actions/attest-build-provenance` (stored in GitHub's attestation store — `gh attestation verify -R tobert/kaibo`, zero extra diff --git a/docs/sandbox-probes.md b/docs/sandbox-probes.md index eb6cca9..377146e 100644 --- a/docs/sandbox-probes.md +++ b/docs/sandbox-probes.md @@ -21,8 +21,9 @@ What we're verifying, concretely: 1. **No write reaches the project** — every mutation path is refused, and nothing lands on real disk. 2. **No external command runs** — the host is unreachable from inside the shell. -3. **No read escapes the root** — paths outside the mount (absolute, `..`, or via a - `path` arg) resolve to nothing; adjacent secrets stay unreadable. +3. **No read escapes the root** — a file read outside the mount (absolute, `..`, or via + a `path` arg) resolves to nothing; adjacent secrets stay unreadable. The mount's own + prefix directories list, and only ever name the next component toward it — Battery C. 4. **No secret leaks via the environment** — the sandbox runs with an empty env. The structural design these probes exercise lives in `src/sandbox.rs` (the four