Skip to content

M0.14: harden verified deployment negative paths - #17

Merged
pgousdal merged 4 commits into
mainfrom
work/m0.14-negative-path-hardening
Sep 5, 2026
Merged

pgousdal merged 4 commits into
mainfrom
work/m0.14-negative-path-hardening

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Implements M0.14 fail-closed negative-path qualification for the verified deployment trust path.

Changes:

  • add explicit EXPECTED_IDENTITY override for testability while preserving the exact production signer identity by default;
  • add scripts/qualify_negative_verification.sh;
  • reject wrong OIDC issuer and wrong signer identity;
  • reject an unsigned unrelated image and a nonexistent release tag;
  • reject invalid runtime and pull selectors and missing VERSION;
  • assert negative paths do not emit an accepted immutable Glowing Bear ref on stdout;
  • integrate the negative matrix into Runtime-neutral verification CI;
  • document M0.14 acceptance criteria.

The signed v0.2.3 release remains the positive qualification target and no existing tag is moved.

@pgousdal
pgousdal merged commit f4094da into main Sep 5, 2026
17 checks passed
@pgousdal
pgousdal deleted the work/m0.14-negative-path-hardening branch September 5, 2026 12:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant