|
| 1 | +// SPDX-License-Identifier: CC-BY-SA-4.0 |
| 2 | +// Copyright (c) Jonathan D.A. Jewell <j.d.a.jewell@open.ac.uk> |
| 3 | += ⚠️ Prototype status, disclaimers & how this fits the ethics work |
| 4 | + |
| 5 | +[.lead] |
| 6 | +*action-trust-layers is a design-stage research prototype (v0), not a |
| 7 | +product.* It floats one idea — borrowing DANE/TLSA's layered pinning model |
| 8 | +for CI supply-chain trust — and shares it openly for critique. |
| 9 | + |
| 10 | +== What "prototype" means here |
| 11 | + |
| 12 | +* *Design / v0.* This is closer to a proposal than a tool. The model, |
| 13 | + `atl.toml` schema, CLI and evaluation semantics are all provisional and |
| 14 | + may change or be dropped. See link:DESIGN.adoc[DESIGN.adoc] for the |
| 15 | + intended architecture and roadmap. |
| 16 | +* *Unproven.* The trust model has not been formally analysed or |
| 17 | + independently reviewed. Treat every claim as a hypothesis to be tested. |
| 18 | +* *No warranty.* Provided "as is", with no warranty of any kind, to the |
| 19 | + extent permitted by the licence. See `LICENSE` / `LICENSES`. |
| 20 | + |
| 21 | +== Trust disclaimer (please read) |
| 22 | + |
| 23 | +This project is *about deciding what to trust*, which makes over-trusting it |
| 24 | +particularly tempting. Please don't. |
| 25 | + |
| 26 | +* *Not a substitute for SHA-pinning yet.* Full recursive commit-SHA pinning |
| 27 | + is the boring, bulletproof baseline. Until this model is implemented, |
| 28 | + reviewed and battle-tested, do not weaken that baseline on its say-so. |
| 29 | +* *A trust policy can be wrong.* "Anchor" and "provenance" layers admit |
| 30 | + actions on softer evidence than an exact hash. That is the whole point — |
| 31 | + and also exactly where a mistake becomes a supply-chain foothold. Any real |
| 32 | + deployment needs its own threat model and review. |
| 33 | +* *Security-relevant, not security-audited.* Nothing here has had a security |
| 34 | + audit. Do not place it on a critical trust path in production. |
| 35 | + |
| 36 | +== Interest and collaboration warmly welcome |
| 37 | + |
| 38 | +This is published to *invite scrutiny of the idea*, not to ship a tool. |
| 39 | + |
| 40 | +* Open an *issue* or *discussion* with attacks, edge cases, "this degrades |
| 41 | + unsafely when…", or prior art we should know about. |
| 42 | +* Critique of the *ethics/trust framing* (below) is especially valued. |
| 43 | +* See `MAINTAINERS.adoc`, `GOVERNANCE.adoc` and `SECURITY.md` before |
| 44 | + contributing. |
| 45 | + |
| 46 | +== Where the ethics thinking lives |
| 47 | + |
| 48 | +Supply-chain trust is an *ethics* question as much as a security one — who |
| 49 | +gets the benefit of the doubt, and who carries the risk when it is misplaced. |
| 50 | +That reasoning is developed in dedicated sibling projects across the estate: |
| 51 | + |
| 52 | +[cols="1,3",options="header"] |
| 53 | +|=== |
| 54 | +| Project | Role in the ethics picture |
| 55 | + |
| 56 | +| https://github.com/hyperpolymath/phronesis[*Phronesis*] |
| 57 | +| A "practical wisdom" language — the estate's substrate for expressing |
| 58 | + normative reasoning, including judgements about trust and risk. |
| 59 | + |
| 60 | +| https://github.com/hyperpolymath/phronesiser[*Phronesiser*] |
| 61 | +| Adds *normative ethical constraints* to AI agents via Phronesis — the home |
| 62 | + for the *values* behind an allow/deny call. |
| 63 | + |
| 64 | +| https://github.com/hyperpolymath/vexometer[*Vexometer*] |
| 65 | +| The *interaction-ethics / UX* side: an "Irritation Surface Analyser" for |
| 66 | + the human cost of tools. A trust policy that forces brittle, humiliating |
| 67 | + workarounds is a real cost, and this is how it gets named. |
| 68 | + |
| 69 | +| https://github.com/hyperpolymath/conative-gating[*conative-gating*] |
| 70 | +| Sibling prototype applying the same "don't grant blanket permission" |
| 71 | + instinct to *model actions* rather than CI actions. |
| 72 | + |
| 73 | +| https://github.com/hyperpolymath/palimpsest-license[*Palimpsest License*] |
| 74 | +| The ethical-use licence family this repo ships under; its Exhibit A sets |
| 75 | + out shared ethical-use expectations for the code. |
| 76 | +|=== |
| 77 | + |
| 78 | +For the ethics rationale specifically, start with *Phronesiser* (the |
| 79 | +*normative* side) and *Vexometer* (the *human-experience* side). |
0 commit comments