Skip to content

security: harden release provenance validation - #377

Open
codeforester wants to merge 1 commit into
mainfrom
security/376-20260930-v1-0-harden-release-provenance-gate-after-post-merge-review
Open

codeforester wants to merge 1 commit into
mainfrom
security/376-20260930-v1-0-harden-release-provenance-gate-after-post-merge-review

Conversation

@codeforester

@codeforester codeforester commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Follow up on the post-merge correctness and coverage review of #375.

  • Treat missing event payloads and all Git inspection failures as explicit validation errors.
  • Fail closed when shallow-repository state cannot be determined.
  • Exercise the production validator entrypoint, event payload parsing, deleted-tag handling, and shallow-query failure paths.
  • Assert provenance dependencies independently for publication, attestation, and GitHub Release jobs.
  • Centralize v-prefixed tag validation for both release validators.
  • Simplify the PyPI dispatch condition.

Validation

  • Full test suite: 401 passed
  • Targeted provenance/workflow tests: 20 passed
  • Ruff check and format check pass
  • Strict mypy pass for the package and typed consumer
  • git diff --check pass

Review follow-up

This addresses the actionable comments posted after #375 merged, including the missing-event Path('.') guard, fail-open shallow-state query, deleted-tag coverage, production-entrypoint coverage, per-job workflow assertions, duplicate tag-prefix logic, and the redundant production-release expression.

Fixes #376

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v1.0] Harden release provenance gate after post-merge review

1 participant