Skip to content

Reproducible build verification expansion #59

@truthixify

Description

@truthixify

Tier: M (2-4 days) Type: tooling

Context

PR #46 set up the reproducible build pipeline. We need to actually use it: run it weekly, verify the deployed testnet contracts match published attestations, expose the verification status publicly.

Scope

  • Weekly GitHub Action that runs the build + verify cycle
  • Publishes verification status to a JSON file in the repo (consumable by status pages)
  • Slack/Discord webhook on failure
  • Public verify.usewraith.xyz page (could be just a GitHub Pages site) showing latest status

Acceptance criteria

  • Weekly CI job
  • status.json published in the repo
  • Webhook config (or doc explaining how to set one up)
  • Public status page online or scaffolded

Files to start with

  • .github/workflows/stellar-attestation.yml (existing)
  • stellar/build/verify.js

Metadata

Metadata

Assignees

No one assigned

    Labels

    Stellar WaveIssues in the Stellar wave programdripsFunded via Drips Networkhelp wantedExtra attention is neededsecuritySecurity-sensitive workstellarTouches Stellar / Soroban codetoolingBuild / tooling work

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions