Skip to content

fix(release): recover staged publication verification - #121

Merged
f0rr0 merged 1 commit into
mainfrom
f0rr0/fix-attestation-bundle-canonicalization
Aug 9, 2026
Merged

fix(release): recover staged publication verification#121
f0rr0 merged 1 commit into
mainfrom
f0rr0/fix-attestation-bundle-canonicalization

Conversation

@f0rr0

@f0rr0 f0rr0 commented Aug 9, 2026

Copy link
Copy Markdown
Owner

Summary

  • accept only the known empty RFC3161 representation difference between actions/attest and gh verification
  • bind recovery to the exact failed GitHub-staged boundary and frozen F4 payload evidence
  • qualify the controller with lightweight recovery-control CI while retaining the original full-payload CI as publication authority
  • preserve legacy recovery provenance and document the exact recovery rules

Validation

  • focused recovery and workflow suite: 228 passed
  • full release suite: 1,403 passed, 6 platform skips; the sole test-policy finding was fixed and reverified
  • full policy suite: 195 passed, 9 platform skips
  • workflow gates: actionlint, zizmor, 55 Node workflow tests, and 12 bootstrap tests passed
  • publication-candidate verification confirms zero product-semantic changes for all 18 products
  • independent correctness and security review found no blocker

Release safety

The immutable 0.1.1 payload remains sourced only from full CI run 31276212829 at ae3d29b. The controller neither rebuilds nor relabels package bytes.

Preserve the frozen F4 payload while qualifying an exact control-only recovery commit. Verify the pinned GitHub-staged boundary and tolerate only Sigstore empty RFC3161 protobuf canonicalization.

Oliphaunt-Release-Recovery-Of: ae3d29b
@f0rr0
f0rr0 merged commit 393cdd7 into main Aug 9, 2026
36 of 46 checks passed
@f0rr0
f0rr0 deleted the f0rr0/fix-attestation-bundle-canonicalization branch August 9, 2026 01:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant