mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 18:05:31 +02:00
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
21 lines
1.2 KiB
JSON
21 lines
1.2 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"helperAbi": 3,
|
|
"state": "pending",
|
|
"platforms": ["linux/amd64", "linux/arm64"],
|
|
"scanners": ["gitleaks", "osv", "semgrep", "zizmor", "trivy", "schemathesis"],
|
|
"requiredChecks": [
|
|
"native image build from a reviewed immutable upstream digest",
|
|
"verified upstream and wrapper provenance plus SPDX SBOM",
|
|
"exact version-output hash through the fixed entrypoint",
|
|
"adapter feature contract and representative output normalization",
|
|
"network-none target execution with read-only source and exact cleanup",
|
|
"secret canary redaction and malformed-output failure",
|
|
"Semgrep rules or OSV/Trivy database content hash matches reviewed input",
|
|
"OSV and Trivy complete a representative scan with no network",
|
|
"Schemathesis reaches only an admitted loopback fixture and completes selected operations"
|
|
],
|
|
"promotion": "CI emits a complete immutable catalog proposal. Only an environment-approved run from protected main may open the source-controlled catalog promotion PR.",
|
|
"rollback": "Restore the previous compatible scanner catalog revision; never replace a missing profile with a host executable or mutable image tag."
|
|
}
|