Skip to content

[External Validation] audit/audit.certification_current_evidence - audit-owner #13

Description

@tradecatlabs

External Validation Work Item

  • Work item: external-work.73d8aad8591d4bd8
  • Domain: audit
  • Category: audit.certification_current_evidence
  • Owner: audit-owner
  • Priority: P0
  • Occurrences: external.1896c711e3d565c8, external.2163cef091103a2a, external.2b48f2930d3f4efc, external.2e0d555c79719bb6, external.329e46834aac1a8c, external.3e715dac715db67b, external.6fb943726b1c4d8c, external.7f9a03088d86c3b8, external.855c7095b96c421c, external.a330a34e8185a8e5, external.cc93a499f9b15c1f, external.eac55560fe0f60b9, external.ed1f68d0f763c865

Required Credentials

  • GitHub Actions read access
  • current local evidence directory
  • current release/audit/certification sidecar evidence

Required Evidence

  • current release proof/live release/audit bundle sidecars are current when used
  • measurement infrastructure certification summary attached

Operator Commands

  • bash scripts/current-audit-bundle.sh --output-dir <audit-output-dir> --local-ci-output-dir <local-ci-output-dir>
  • bash scripts/external-validation-proof-ref-gate.sh --work-queue-json <work-queue-json> --evidence-json <proof-ref-bundle-json> --output-json <proof-ref-gate-json>
  • bash scripts/measurement-infrastructure-certification.sh --evidence-dir <dir> --output-json <path>
  • bash scripts/measurement-infrastructure-certification.sh --evidence-dir <local-ci-output-dir> --output-json <certification-json>

Proof Ref Template

  • Pattern: evidence://external-validation/audit-certification-current-evidence/<run-id>
  • Artifact hash: sha256:<64 lowercase hex artifact digest>
  • Verification command: bash scripts/external-validation-proof-ref-gate.sh --work-queue-json <work-queue-json> --evidence-json <proof-ref-bundle-json> --output-json <proof-ref-gate-json>

Blocking Items

  • category_live_evidence_missing
  • category_live_pending
  • proof_ref_missing
  • stale_owner_pending

Closure Condition

Current release, live gate, audit bundle, proof-ref gate and category runbooks are all regenerated for the same commit.

Non-Claims

  • This issue does not prove live validation has passed.
  • Do not paste token, secret, DSN, endpoint URL, chat id, user input, report body or production logs.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions