Validate descendant provenance across conformance consumers - #295
Merged
Merged
Conversation
GitHub's provenance names the commit a workflow run started from. When a protected run is dispatched against a named merged revision, that is the ref tip rather than the revision, so signerDigest and sourceDigest could never equal the frozen producer commit and the binding refused every non-tip producer. The lock now carries the descent from the attested source down to the producer commit, and the binding proves each link against real Git parents exactly as it already does for the authority path. An absent descent still means the two must be equal, so existing tip-only locks and the frozen review fixtures validate unchanged. Descent alone would be a weakening. The run that signs the attestation executes the workflow as it exists at the attested source, not at the producer commit, and only the producer commit's copy was ever verified against the reviewed digest. The evidence path now verifies the workflow bytes at the attested source too, so a descendant cannot attest evidence produced by an unreviewed workflow. Refs OpenCoven/chat#314
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Descent schema, type declarations, caller wiring, and source workflow graph support remain incomplete.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 2
Open (2)
What changed in this PR
Adds provenance source-descent support for validating protected runs against named merged revisions while preserving tip-only compatibility.
Changes:
- Validates source descent and Git parent lineage.
- Verifies workflow content at the attested source revision.
- Updates types, fixtures, locks, and tests.
| File | Reviewed changes |
|---|---|
tests/conformance-gaps.spec.ts |
Updates producer fixtures for source-descent behavior. |
tests/conformance-contract.spec.ts |
Adds descent parsing coverage; parent-walk edge coverage remains incomplete. |
scripts/github-conformance-evidence.mjs |
Adds source workflow verification, but descent wiring and producer-revision graph support remain incomplete. |
scripts/conformance-contract.mjs |
Adds descent validation, though its authority schema does not yet accept the descent records. |
scripts/conformance-contract.d.mts |
Updates declarations but is missing the descent property on the authority parameter. |
conformance/client-v1-cross-repository-lock.json |
Records the empty tip-only descent for compatibility. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Sep 19, 2026
Merged
Closed
This was referenced Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

A protected conformance run may start at a descendant of the reviewed producer revision. Previously the lock accepted that shape, but the authority schema, evidence collectors, and run identity checks could not validate it.
This change carries actual Git ancestry through both collectors, verifies the reviewed workflow at the producer and dispatch source, and binds run, job, deployment, artifact, and certificate identities to the dispatch source. The platform harness remains bound to the reviewed producer revision. It also validates Chat's producer-revision resolver as an exact protected workflow graph, including its successful resolver job.
Absent or empty descent preserves tip-only behavior. The current frozen lock remains tip-only; exercising descendant dispatch requires a fresh reviewed binding with the resolver present at both revisions. Publication remains disabled, and real three-platform conformance is still tracked in #38.
Validation on 9615b56:
corepack pnpm@10.34.0 verify: 80 files, 2,696 passed, 2 skipped; coverage, contracts, packed consumers, stress tests, type checking, and lint passed.These are conformance tooling changes; the public package API is unchanged.