feat: add two-domain PoCI cross-repository federation - #201
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Validation completeFinal head: Passed:
Federation result:
Evidence artifact:
Honest boundary: ProofPath and Ibex use separate repositories, commits, workflows, runners, artifacts, recomputation paths, and Sigstore identities; both repositories are still controlled by the same GitHub account owner. |
What changed
Adds the ninth PoCI slice: a two-domain federation between ProofPath and an external Ibex consumer.
The implementation adds:
Federation chain
Reviewer expectation
Exact-byte boundary
Sigstore signs subject bytes rather than semantic JSON. The committed producer report and Ibex receipt therefore preserve the exact formatting and SHA-256 bytes that were attested in their source workflows.
Trust boundary
ProofPath and Ibex now have separate repositories, commits, workflows, runners, artifacts, independent graph recomputation, and different Sigstore identities. Both repositories are currently controlled by the same GitHub account owner, so this demonstrates repository/workflow federation rather than independent organizational governance.
Stacked PR
Base:
agent/poci-signed-multirunner-witness-v0.1/ #200Consumes Ibex external-consumer PR #74 at head
1426154d18f646f37c9d281ba4d9b5d45d808c92and its successful keyless receipt attestation.No merge is performed by this PR.