Skip to content
This repository was archived by the owner on Aug 18, 2026. It is now read-only.

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

release-oras-spike

Throwaway scratch repository for meigma/release architecture spike B: does oras-go v2 reproduce the current ORAS 1.3.3 publication contract on GHCR, and can all trust metadata precede public tags?

Not a product. Safe to delete once the spike verdict is recorded in the meigma/release session journal.

  • main.go, layout.go, publish.go — probe program. -mode=local runs everything against an in-process registry with no network.
  • .github/workflows/spike.yml — GHCR phase: publish by digest, sign, attest three subjects, inspect referrers, then tag last and re-verify.

About

Throwaway scratch repo for release-cli architecture spike B (oras-go v2 GHCR parity). Safe to delete.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages