feat: add portable PoCI external witness SDK - #204
Conversation
|
Important Review skippedDraft detected. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Validation completeFinal head: Passed:
Distributable evidence artifact:
Honest result: this repository attested the SDK kit, not an independent operator response. A same-owner run cannot claim organizational independence. No merge has been performed. |
What changed
Adds the eleventh PoCI slice: a portable onboarding kit for an independently owned external witness repository.
The kit contains:
HOLD, builds a deterministic kit manifest, keyless-attests that manifest, and uploads a distributable artifact.External operator flow
Honest same-owner behavior
This repository cannot manufacture an independent operator response for itself. The live SDK conformance workflow is expected to produce:
It attests only the distributable SDK kit manifest, not a fake external response.
Trust boundary
The reference workflow runs in another repository and gets a separate owner/workflow/Sigstore identity. It currently reuses the pinned ProofPath graph builder as a reproducible reference implementation. It therefore demonstrates owner-diverse execution, not yet independently implemented algorithm diversity.
Stacked PR
Base:
agent/poci-organizational-independence-gate-v0.1/ #202The kit is intended for the external operator requested in issue #203.
No merge is performed by this PR.