release: verify and attest published release evidence#433
Conversation
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
dc82f31 to
888008b
Compare
571a402 to
07600e9
Compare
Signed-off-by: Jeremi Joslin <jeremi@joslin.fr>
|
Release and security review verdict: please do not merge as-is. Required changes:
The verifier is useful, but the stale-evidence path is a release-integrity blocker for this PR. This improvement itself is not required for beta-16. |
|
Fresh beta-16 review at head 76fbbaa: please keep this stacked draft out of the current release train. Required before reconsideration:
This PR changes workflows, evidence schemas, and asset verification, so merging it after beta-16 preparation would invalidate candidate evidence unless the train were restarted. |
|
Closing as not planned after the post-beta cost review. Signed Releases already passes at 10/10, and the existing workflow reconciles checksums, signatures, provenance, and published assets. PR #431 replaces this large evidence-bundle design with the smaller publish-once guard and fix-forward policy. |
Stacked on the documentation-cache PR. Implements the clean-room verifier, evidence bundle, and command-entrypoint recommendations from #427.
Verification:
The live before/after rehearsal measurement remains a post-merge operational step because it requires a real GitHub release run. Part of #427.