Skip to content

Add verified CLI self-update - #24

Merged
konojunya merged 1 commit into
mainfrom
agent/safe-self-update
Sep 5, 2026
Merged

konojunya merged 1 commit into
mainfrom
agent/safe-self-update

Conversation

@konojunya

Copy link
Copy Markdown
Member

Summary

  • add stack update check/install/exact-version contract for receipted direct GitHub installations
  • authenticate release manifest and archive, validate deterministic archive, and replace with rollback
  • refuse package-manager/unknown ownership and keep self-update planned until installer/release activation
  • attest manifests in release workflow and preserve compatibility floor in distribution contract

Safety

  • exact repository/workflow/tag/commit/OIDC/GitHub-hosted runner attestation constraints
  • bounded metadata/artifacts, symlink/type checks, package-manager path refusal, debug override absent from release binaries
  • existing binary preserved on digest/attestation/permission/candidate/receipt-commit failures

Verification

  • Rust stable + 1.85 tests and Clippy
  • exact specification conformance/template checks
  • line 90.06%, function 97.28%, region 90.97% coverage
  • release/documentation build, Node release/distribution/supply-chain suites, Python packaging suites
  • cargo audit: 76 dependencies, no advisories
  • live v0.3.0 archive attestation verified with the same client constraints

@konojunya
konojunya merged commit 1b43e5f into main Sep 5, 2026
2 checks passed
@konojunya
konojunya deleted the agent/safe-self-update branch September 5, 2026 08:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant