mirror of
https://github.com/garrytan/gstack.git
synced 2026-09-16 18:05:31 +02:00
* feat(cso): add verified audits and replayable repair bundles * fix(cso): harden qualification and setup boundaries * fix(cso): assemble security canaries at runtime * fix(cso): bound release proof and maintenance work Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): require complete evaluation reports Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): replay expired snapshots from supplied source Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): synchronize DNS cancellation assertion Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore(ship): exempt repository owner from liveness proof Co-Authored-By: OpenAI Codex <noreply@openai.com> * test(cso): make recheck retention overlap deterministic Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: bump version and changelog (v1.85.0.0) Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass native release gates Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.86.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): resolve rechecks by finding Co-Authored-By: OpenAI Codex <noreply@openai.com> * chore: move release to v1.87.0.0 Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): pass macOS and Windows release gates Normalize BSD wc output, compare Windows paths by filesystem identity, preserve portable snapshot race coverage, and narrow POSIX-only Windows fixtures. Co-Authored-By: OpenAI Codex <noreply@openai.com> * fix(cso): harden native verification gates * fix(cso): refine Windows native diagnostics * test(cso): isolate Windows Git startup failure * test(cso): stabilize Windows native diagnostics * fix(cso): support hardened Git on Windows * fix(cso): close final verification gaps * test(cso): bound cold Docker fixture setup * fix(cso): restore cross-platform free-suite gates --------- Co-authored-by: OpenAI Codex <noreply@openai.com>
34 lines
1.8 KiB
JSON
34 lines
1.8 KiB
JSON
{
|
|
"schemaVersion": 1,
|
|
"helperAbi": 3,
|
|
"state": "enforced",
|
|
"buildRevision": "cso-runtime-inputs-2026-09-10",
|
|
"platforms": ["linux/amd64", "linux/arm64"],
|
|
"profiles": ["node", "bun", "python", "rails", "postgresql"],
|
|
"statementArtifact": "cso-qualified-runtime-statements",
|
|
"statementFilename": "qualified-runtime.json",
|
|
"requiredInputs": [
|
|
"reviewed native base and SBOM generator manifests",
|
|
"exact runtime and package-manager versions verified inside the selected base",
|
|
"immutable staged runtime digest",
|
|
"trusted protected-main source commit and workflow run",
|
|
"verified SBOM and provenance digests"
|
|
],
|
|
"requiredChecks": [
|
|
"non-root/read-only/capability/seccomp admission",
|
|
"IPv4/IPv6/DNS and metadata egress denied",
|
|
"secretless cold acquisition and offline boot",
|
|
"application verifier positive and deliberately failing assertions",
|
|
"lifecycle and native build hooks execute only offline",
|
|
"Rails SQLite and PostgreSQL, all connections, native gem cold start",
|
|
"one held-out reproduced defect and runtime-tested repair per application stack",
|
|
"watchdog survival and exact resource cleanup",
|
|
"secret-canary containment",
|
|
"daily precision and comprehensive high/critical recall release thresholds",
|
|
"signed provenance verification and SBOM digest"
|
|
],
|
|
"promotion": "The protected promotion workflow accepts exactly ten authenticated same-run qualified-runtime.json statements and emits an attested source-review candidate. It never writes the catalog.",
|
|
"externalPrerequisite": "A successful protected-main qualification run must upload cso-qualified-runtime-statements after private held-out and accuracy gates finish. No such artifact exists until those external gates actually pass.",
|
|
"rollback": "Select the prior compatible helper/catalog pair; never fall back to a mutable tag."
|
|
}
|