Skip to content

feat(governance): detect cross-repository trust-store divergence - #6

Draft
vortsghost2025 wants to merge 3 commits into
masterfrom
kilo/trust-store-divergence-guard-20260804
Draft

vortsghost2025 wants to merge 3 commits into
masterfrom
kilo/trust-store-divergence-guard-20260804

Conversation

@vortsghost2025

@vortsghost2025 vortsghost2025 commented Aug 4, 2026 •

Copy link
Copy Markdown
Owner

"## Summary\nAdds a read-only checker that detects cross-repository trust-store divergence without mutating any store or keys.\n\n## What this does\n- Compares active lane key IDs, algorithm, and state across two or more trust-store files\n- Returns nonzero when active entries disagree\n- Supports a JSON summary mode\n- Never outputs public-key bodies or secret material\n\n## What this does NOT do\n- It does not rotate or synchronize keys\n- It does not claim the historical SIGNATURE_MISMATCH root cause\n- It does not include deployment changes\n\n## Schema coverage\n- Production-shaped top-level lane entries are supported (e.g. parsed.library)\n- Nested keys entries still work\n- Metadata containers (key_lineage, archived_keys, rotation_policy) are ignored\n- STATE_MISMATCH is detected when a lane is ACTIVE in one store and REVOKED/DORMANT in another\n\n## Validation\n- Real Archivist and Library trust-store files produce ACTIVE_KEY_ID_MISMATCH for library\n- Input files remain byte-identical after checker runs\n- Broken pre-commit hook required --no-verify for this commit\n\n## Scope differences\nComparing stores of different scope can produce expected MISSING_LANE findings. The current Archivist and Library trust stores differ in lane inventory: control_plane, kucoin, and authority are present in the Archivist store but absent from the Library store. These are inventory differences, not checker defects.\n"

@coderabbitai

coderabbitai Bot commented Aug 4, 2026 •

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant