Skip to content

Record SLSA Build Level 3 assessment - #70

Merged
bordumb merged 2 commits into
mainfrom
codex/slsa-build-l3-assessment
Aug 3, 2026
Merged

Record SLSA Build Level 3 assessment#70
bordumb merged 2 commits into
mainfrom
codex/slsa-build-l3-assessment

Conversation

@bordumb

@bordumb bordumb commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

What changed

  • records a repository-owner-delegated SLSA 1.2 Build Level 3 assessment against successful preparation run 30849197798
  • binds the result to reusable-builder SHA-256 e2762ffe4ee2aa2c76c79f7382b2ac4913582a21630907c27fa0a517a1c7c25d
  • makes finalization copy the assessment and assessed workflow into staged evidence and digest-bind both in the release manifest
  • changes the manifest assessment status to passed only after fail-closed validation of the complete requirement set
  • adds a regression test proving changed builder bytes stale the assessment and block the release
  • advances the release semantic-freeze inventory and identity to version 14

Evidence

Validation

Locally passed before push:

  • cargo test -p xtask — 46 passed
  • cargo xtask release-contract
  • cargo xtask semantic-freeze
  • cargo xtask public-naming
  • cargo xtask arch
  • cargo fmt --all --check
  • JSON parsing and git diff --check
  • exact reusable-builder SHA-256 verification

GitHub CI remains the merge authority. This PR deliberately does not rerun the full release preparation locally.

Affected claims

This PR permits the exact statement that the assessed reusable builder satisfies the applicable SLSA 1.2 Build Level 3 producer/build-platform requirements while its workflow bytes and GitHub-hosted boundary remain unchanged.

It does not strengthen Auths protocol, formal-proof, provider, product-readiness, compliance, or audit claims.

Exclusions

This PR does not:

  • create or move auths-v1.0.0-rc.1
  • create a GitHub prerelease
  • publish to crates.io, npm, or PyPI
  • upload secrets or configure repository environments
  • provide an independent security audit
  • authorize promotion or registry publication

Remaining gates

After merge:

  1. rerun both isolated release preparations against the exact merged commit;
  2. require every hosted check, provenance verification, reproducibility comparison, and offline staging check to pass;
  3. obtain exact repository-owner authorization for the new commit and manifest digest;
  4. authorize GitHub prerelease promotion separately;
  5. complete the Phase 8 exact-claim PR;
  6. complete Phase 9 independent security review before any external-review claim.

Rollback before tag creation is a normal revert or replacement candidate-closure PR. Once a candidate tag exists, it must never be moved; remediation requires withdrawal and a new RC ordinal.

bordumb added 2 commits August 3, 2026 22:19
Signed-off-by: bordumb <bordumbb@gmail.com>
Auths-Id: did:keri:EMN-WRXNAkLfavKsaFHS0ehP7eB1s8a1alktBJoDhI7b
Auths-Device: did:keri:EAswoxxXY6-kXqYcc3mUngY8GOiwhDwXxFfjWXzCvuW6
Auths-Anchor-Seq: 1
Signed-off-by: bordumb <bordumbb@gmail.com>
Auths-Id: did:keri:EMN-WRXNAkLfavKsaFHS0ehP7eB1s8a1alktBJoDhI7b
Auths-Device: did:keri:EAswoxxXY6-kXqYcc3mUngY8GOiwhDwXxFfjWXzCvuW6
Auths-Anchor-Seq: 1
@bordumb
bordumb merged commit b6827b6 into main Aug 3, 2026
@bordumb
bordumb deleted the codex/slsa-build-l3-assessment branch August 3, 2026 21:39
@bordumb

bordumb commented Aug 3, 2026

Copy link
Copy Markdown
Contributor Author

Candidate-closure addendum

The merged second commit, b1922bf, also:

  • adds release/README.md and the step-by-step release/RELEASE_RUNBOOK.md;
  • defines canonical auths.owner-release-authorization/1 records;
  • requires the immutable repository-owner identity and exact commit, tag, manifest, preparation run, destination, timestamp, and authorization statement;
  • rejects unknown, reordered, pretty-printed, digest-mismatched, or candidate-mismatched authorization bytes;
  • preserves the authorization record and promotion request with the prerelease evidence;
  • digest-binds RELEASE_CANDIDATE_NOTES.md in the release manifest and uses those staged bytes as the GitHub prerelease description; and
  • advances the release semantic-freeze inventory and public-surface identity to version 15.

Validation completed before push:

  • cargo test -p xtask — 49 passed;
  • cargo xtask release-contract;
  • cargo xtask semantic-freeze;
  • cargo xtask public-naming;
  • cargo xtask arch;
  • cargo fmt --all --check;
  • actionlint .github/workflows/release.yml;
  • JSON parsing, workflow-digest verification, and git diff --check.

Affected claim: promotion now has an integrity-bound, candidate-specific repository-owner authorization record. This does not claim an independent security audit, protocol correctness, production readiness, registry publication, or external review.

No tag, prerelease, package, secret, or external-review state was created by this change. The exact merged commit must pass required main CI and a fresh two-run preparation before any separate promotion authorization.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant