Add signal contracts for reachability, exploitability, trust, and unknown symbols
- Introduced `ReachabilityState`, `RuntimeHit`, `ExploitabilitySignal`, `ReachabilitySignal`, `SignalEnvelope`, `SignalType`, `TrustSignal`, and `UnknownSymbolSignal` records to define various signal types and their properties. - Implemented JSON serialization attributes for proper data interchange. - Created project files for the new signal contracts library and corresponding test projects. - Added deterministic test fixtures for micro-interaction testing. - Included cryptographic keys for secure operations with cosign.
This commit is contained in:
6
etc/secrets/dsse-dev.signing.json
Normal file
6
etc/secrets/dsse-dev.signing.json
Normal file
@@ -0,0 +1,6 @@
|
||||
{
|
||||
"keyId": "notify-dev-hmac-001",
|
||||
"secret": "ZGV2ZWxvcG1lbnQtc2lnbmluZy1rZXktZm9yLXRlc3Rpbmctb25seQ==",
|
||||
"algorithm": "HMACSHA256",
|
||||
"note": "Development-only HMAC key for DSSE signing. DO NOT use in production. Secret is base64 of 'development-signing-key-for-testing-only'."
|
||||
}
|
||||
Reference in New Issue
Block a user