Skip to content

fix: bind release evidence to exact archive contents - #32

Merged
codeforester merged 1 commit into
mainfrom
bug/23-20260917-bug-bind-release-evidence-to-the-actual-archive-inventory
Sep 17, 2026
Merged

codeforester merged 1 commit into
mainfrom
bug/23-20260917-bug-bind-release-evidence-to-the-actual-archive-inventory

Conversation

@codeforester

Copy link
Copy Markdown
Contributor

Summary

Validate exact SPDX inventory, hashes, package relationships and source identities against the archive; bind structured provenance to subject and dependencies. Reject duplicate JSON keys and mismatched JSON types. Validate all archive paths/types before safe extraction. Default verification executes no payload code; --trusted-smoke is explicit opt-in. Retain offline vendor integrity checks and document consistency versus authenticity.

Validation

Full ./tests/validate.sh passed: 27 BATS cases, independent SPDX validation, cross-timezone reproducibility, standalone trusted smoke, and 22 coherent-checksum/unsafe-archive/execution-boundary regressions. Synthetic fixtures only.

Fixes #23

@codeforester
codeforester merged commit 777b7a8 into main Sep 17, 2026
12 checks passed
@codeforester
codeforester deleted the bug/23-20260917-bug-bind-release-evidence-to-the-actual-archive-inventory branch September 17, 2026 16:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

bug: bind release evidence to the actual archive inventory

1 participant