Files
gstack/lib/cso/images/qualification.json
Garry TanandOpenAI Codex 4a3c6a8a3c v1.87.0.0 feat: add verified CSO audits and replayable repair bundles (#2852)
* feat(cso): add verified audits and replayable repair bundles

* fix(cso): harden qualification and setup boundaries

* fix(cso): assemble security canaries at runtime

* fix(cso): bound release proof and maintenance work

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): require complete evaluation reports

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): replay expired snapshots from supplied source

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): synchronize DNS cancellation assertion

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore(ship): exempt repository owner from liveness proof

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* test(cso): make recheck retention overlap deterministic

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: bump version and changelog (v1.85.0.0)

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass native release gates

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.86.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): resolve rechecks by finding

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* chore: move release to v1.87.0.0

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): pass macOS and Windows release gates

Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures.

Co-Authored-By: OpenAI Codex <noreply@openai.com>

* fix(cso): harden native verification gates

* fix(cso): refine Windows native diagnostics

* test(cso): isolate Windows Git startup failure

* test(cso): stabilize Windows native diagnostics

* fix(cso): support hardened Git on Windows

* fix(cso): close final verification gaps

* test(cso): bound cold Docker fixture setup

* fix(cso): restore cross-platform free-suite gates

---------

Co-authored-by: OpenAI Codex <noreply@openai.com>
2026-09-14 15:14:58 -07:00

34 lines
1.8 KiB
JSON

{
"schemaVersion": 1,
"helperAbi": 3,
"state": "enforced",
"buildRevision": "cso-runtime-inputs-2026-09-10",
"platforms": ["linux/amd64", "linux/arm64"],
"profiles": ["node", "bun", "python", "rails", "postgresql"],
"statementArtifact": "cso-qualified-runtime-statements",
"statementFilename": "qualified-runtime.json",
"requiredInputs": [
"reviewed native base and SBOM generator manifests",
"exact runtime and package-manager versions verified inside the selected base",
"immutable staged runtime digest",
"trusted protected-main source commit and workflow run",
"verified SBOM and provenance digests"
],
"requiredChecks": [
"non-root/read-only/capability/seccomp admission",
"IPv4/IPv6/DNS and metadata egress denied",
"secretless cold acquisition and offline boot",
"application verifier positive and deliberately failing assertions",
"lifecycle and native build hooks execute only offline",
"Rails SQLite and PostgreSQL, all connections, native gem cold start",
"one held-out reproduced defect and runtime-tested repair per application stack",
"watchdog survival and exact resource cleanup",
"secret-canary containment",
"daily precision and comprehensive high/critical recall release thresholds",
"signed provenance verification and SBOM digest"
],
"promotion": "The protected promotion workflow accepts exactly ten authenticated same-run qualified-runtime.json statements and emits an attested source-review candidate. It never writes the catalog.",
"externalPrerequisite": "A successful protected-main qualification run must upload cso-qualified-runtime-statements after private held-out and accuracy gates finish. No such artifact exists until those external gates actually pass.",
"rollback": "Select the prior compatible helper/catalog pair; never fall back to a mutable tag."
}