Repository navigation
feat(governance): detect cross-repository trust-store divergence - #6
Draft
vortsghost2025 wants to merge 3 commits into
Draft
vortsghost2025 wants to merge 3 commits into
vortsghost2025 wants to merge 3 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
…vergence-guard-20260804
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
"## Summary\nAdds a read-only checker that detects cross-repository trust-store divergence without mutating any store or keys.\n\n## What this does\n- Compares active lane key IDs, algorithm, and state across two or more trust-store files\n- Returns nonzero when active entries disagree\n- Supports a JSON summary mode\n- Never outputs public-key bodies or secret material\n\n## What this does NOT do\n- It does not rotate or synchronize keys\n- It does not claim the historical SIGNATURE_MISMATCH root cause\n- It does not include deployment changes\n\n## Schema coverage\n- Production-shaped top-level lane entries are supported (e.g.
parsed.library)\n- Nestedkeysentries still work\n- Metadata containers (key_lineage,archived_keys,rotation_policy) are ignored\n- STATE_MISMATCH is detected when a lane is ACTIVE in one store and REVOKED/DORMANT in another\n\n## Validation\n- Real Archivist and Library trust-store files produceACTIVE_KEY_ID_MISMATCHforlibrary\n- Input files remain byte-identical after checker runs\n- Broken pre-commit hook required--no-verifyfor this commit\n\n## Scope differences\nComparing stores of different scope can produce expectedMISSING_LANEfindings. The current Archivist and Library trust stores differ in lane inventory:control_plane,kucoin, andauthorityare present in the Archivist store but absent from the Library store. These are inventory differences, not checker defects.\n"