Skip to content

Add signed pack trust verification - #38

Merged
egrexsec merged 3 commits into
mainfrom
feature/pack-trust
May 29, 2026
Merged

egrexsec merged 3 commits into
mainfrom
feature/pack-trust

Conversation

@egrexsec

Copy link
Copy Markdown
Owner

Summary

Implements trust-oriented pack verification workflows for DetLab.

Changes

  • Added trust verification module
  • Added SHA256 checksum verification
  • Added trust metadata generation
  • Added pack integrity validation workflows
  • Added trust verification tests
  • Added documentation for secure pack workflows

Example

detlab pack verify registry/windows-core-1.0.0.tar.gz \
  --metadata registry/windows-core.json

@egrexsec
egrexsec merged commit c3c865f into main May 29, 2026
1 check failed

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: b5325f1f76

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread README.md
Comment on lines +34 to +35
detlab pack verify registry/windows-core-1.0.0.tar.gz \
--metadata registry/windows-core.json

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Wire the documented pack verify command

This new documented workflow is not reachable from the CLI: pyproject.toml points detlab at detlab.main:app, and detlab/main.py only registers the existing top-level commands with no pack Typer sub-app or verify command, while the new trust functions are never imported there. Users following this example will get an unknown-command error instead of pack verification, so the CLI needs to expose this workflow or the docs should not advertise it.

Useful? React with 👍 / 👎.

@egrexsec
egrexsec deleted the feature/pack-trust branch June 16, 2026 12:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant