Skip to content

security: gate releases on reviewed main provenance - #375

Open
codeforester wants to merge 1 commit into
mainfrom
security/271-20260927-v1-0-gate-releases-on-protected-main-and-independent
Open

codeforester wants to merge 1 commit into
mainfrom
security/271-20260927-v1-0-gate-releases-on-protected-main-and-independent

Conversation

@codeforester

@codeforester codeforester commented Sep 26, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • add a fail-closed provenance validator for annotated tags, exact reviewed SHA, trusted main ancestry, complete history, and forced/deleted tag events
  • make publication, attestations, and GitHub Release creation depend on the same provenance job
  • document and test the release contract and negative paths

Repository controls

  • tightened the existing default-branch ruleset to require one approval, stale-review dismissal, last-push approval, strict status checks, and policy/quality/runtime/consumer checks
  • disabled PyPI self-review and administrator bypass; production release now waits for an independent reviewer tracked by [v1.0] Expand maintainer capacity and document project governance #252

Validation

  • full test suite: 391 passed
  • targeted provenance/workflow tests: 11 passed
  • Ruff check, Ruff format check, and strict mypy pass

Fixes #271

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[v1.0] Gate releases on protected main lineage and independent approval

1 participant