Skip to content

Attest release distribution provenance - #25

Closed
biru-codeastromer wants to merge 17 commits into
mainfrom
codex/release-attestations
Closed

Attest release distribution provenance#25
biru-codeastromer wants to merge 17 commits into
mainfrom
codex/release-attestations

Conversation

@biru-codeastromer

@biru-codeastromer biru-codeastromer commented Aug 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • add pinned Sigstore build-provenance attestations for the exact wheel and source archive subjects listed in SHA256SUMS
  • inherit Publish assets before immutable release lock #35 protected publication and Verify release assets before upload #24 exact builder, checksum, draft recovery, and remote-asset verification
  • verify every distribution attestation against the exact release workflow, workflow revision, protected tag ref, and source commit before closure
  • keep GitHub automatic release-attestation verification as a separate publication control

Validation

  • make release-gate: 111 passed, 1 optional skip, 91.83% coverage
  • committed workflow tests assert pinned attestation, exact subjects, signer workflow and digest, protected source ref and digest, exact remote assets, and immutable closure
  • package, dependency, example, text, repository, and Gitleaks audits passed

Integration order is #35, then #24, then this PR. This PR still requires an eligible reviewer approval. No release or tag was created.

@biru-codeastromer

Copy link
Copy Markdown
Contributor Author

The provenance-documentation blocker is fixed at the new head. README now states that v0.2.3 predates the attestation workflow and has no distribution attestations, and uses a version-neutral X.Y.Z verification example for future workflow-produced releases. The corrected #24 checksum scope is also carried forward. Fresh local gate: 101 passed, 1 optional skip, 91.83% coverage, clean installs and all audits green.

@biru-codeastromer

Copy link
Copy Markdown
Contributor Author

Superseded by #37, which preserves the provenance contract on a clean linear history and verifies exact artifact identity before publication.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants