Skip to content

Promote verified readiness receipt source and transport binding - #2872

Merged
twoimo merged 6 commits into
datafrom
develop
Sep 5, 2026
Merged

Promote verified readiness receipt source and transport binding#2872
twoimo merged 6 commits into
datafrom
develop

Conversation

@twoimo

@twoimo twoimo commented Sep 5, 2026

Copy link
Copy Markdown
Owner

Promote the readiness receipt provenance correction from develop to data. The v3 launcher compiles verified Git source directly, creates a fresh connection using the pinned Supabase CA and exact project endpoint, anchors Git/object lookups to the intended checkout with inherited overrides removed and file-based alternate stores rejected, accepts credentials only, and rejects stale transactions before validating repeatable-read/read-only state.

Local validation: 17 targeted tests and 7 reconciliation tests pass, including real PostgreSQL stale-snapshot rejection and poisoned bytecode-cache control. Source verification passes for the committed launcher. Transport success tests are mocked, not hosted evidence. Required CI and branch protection must pass on this promotion before merge.

This is a source promotion only. No hosted v3 receipt, legal review, backup/PITR, production write, or deployment is established. Existing PR #2870 should receive this correction before its original provenance reviews are resolved.

@vercel

vercel Bot commented Sep 5, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
tzudong Ready Ready Preview Sep 5, 2026 10:26am UTC

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review Completed 2026-09-05T10:27:16.907009Z 8f832b4 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@twoimo
twoimo merged commit d10fab6 into data Sep 5, 2026
40 of 41 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant