Skip to content

[External Validation] release/release.artifact_current_commit - release-ops #19

Description

@tradecatlabs

External Validation Work Item

  • Work item: external-work.e5ec45d990955344
  • Domain: release
  • Category: release.artifact_current_commit
  • Owner: release-ops
  • Priority: P0
  • Occurrences: external.65e60a45c0fadf16, external.6a97f87a91b568c7, external.8490bf9389a8fac9, external.be87b4bd8b4b4cd0, external.d495f0bf4ebd0624, external.da4996b32ac673ec

Required Credentials

  • GHCR or registry permissions when publishing
  • GitHub Actions read access
  • GitHub Actions workflow access
  • artifact attestation verification access
  • attestation verification access
  • container registry read access

Required Evidence

  • SBOM/provenance/rollback evidence attached
  • container digest or explicit no-push mode recorded
  • current commit Acceptance run passed
  • current commit Container run passed

Operator Commands

  • bash scripts/current-release-proof.sh --require-current-release --output-json <current-release-proof-json>
  • bash scripts/current-release-proof.sh --require-current-release --output-json <path>
  • bash scripts/external-validation-proof-ref-gate.sh --work-queue-json <work-queue-json> --evidence-json <proof-ref-bundle-json> --output-json <proof-ref-gate-json>
  • bash scripts/live-release-gate.sh --output-json <path>
  • bash scripts/release-artifacts.sh --output-dir <release-artifacts-dir> --summary-json <release-summary-json>

Proof Ref Template

  • Pattern: evidence://external-validation/release-artifact-current-commit/<run-id>
  • Artifact hash: sha256:<64 lowercase hex artifact digest>
  • Verification command: bash scripts/external-validation-proof-ref-gate.sh --work-queue-json <work-queue-json> --evidence-json <proof-ref-bundle-json> --output-json <proof-ref-gate-json>

Blocking Items

  • category_live_evidence_missing
  • category_live_pending
  • proof_ref_missing
  • stale_owner_pending

Closure Condition

Current commit CI, container digest, SBOM/provenance, attestation and rollback evidence all match.

Non-Claims

  • This issue does not prove live validation has passed.
  • Do not paste token, secret, DSN, endpoint URL, chat id, user input, report body or production logs.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions