Skip to content

docs: update historical provenance disclosure draft - #39

Merged
scottconverse merged 1 commit into
mainfrom
docs/historical-provenance-disclosure-draft
May 5, 2026
Merged

scottconverse merged 1 commit into
mainfrom
docs/historical-provenance-disclosure-draft

Conversation

@scottconverse

Copy link
Copy Markdown
Contributor

Summary

  • updates docs/ops/historical-provenance-draft.md with the auditor-requested baseline placeholder, 2026-05-04 backfill counts, audit-contract framing, worked Sigstore verification commands, canonical source/fixture links, and SECURITY.md contact path
  • adds maintainer-environment hygiene rules to docs/ops/release-signing.md so audit-reviewed artifacts live in repo branches/PRs rather than desktop scratchpads
  • keeps the disclosure explicitly marked as draft / not policy publication until the first attested baseline release is authorized and shipped

Release-Class Boundary

Not release-class work. This PR does not delete, recreate, or modify tags; does not edit existing release notes; does not generate or upload attestations against real releases; and does not publish the disclosure as operative policy.

Audit Surface Notes

  • Draft artifact under review: docs/ops/historical-provenance-draft.md
  • Existing tracked draft reference also present in repo: docs/ops/sigstore-release-workflow-draft.yml
  • No maintainer-desktop artifact is being submitted as the review surface; this PR commit is the review surface.

Verification

  • python scripts\verify-release-provenance.py --fixtures-dir tests\fixtures\release_provenance -> 9/9 fixtures passed
  • python -m ruff check civiccore\release_provenance.py scripts\verify-release-provenance.py tests\test_release_provenance.py -> passed
  • bash scripts/verify-release.sh -> 247 pytest passed, ruff passed, version lockstep passed, required docs present, release-provenance fixtures passed, build artifacts generated, clean virtualenv import smoke passed, VERIFY-RELEASE: PASSED
  • scripts/verify-docs.sh is not present in CivicCore; scripts/verify-release.sh is the canonical repo gate for docs/build/test verification.

@scottconverse
scottconverse marked this pull request as ready for review May 5, 2026 05:14
@scottconverse
scottconverse merged commit 3b77993 into main May 5, 2026
1 check passed
@scottconverse
scottconverse deleted the docs/historical-provenance-disclosure-draft branch May 5, 2026 05:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant