Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
Findings Ledger CI / build-test (push) Has been cancelled
Findings Ledger CI / migration-validation (push) Has been cancelled
Scanner Analyzers / Discover Analyzers (push) Has been cancelled
Signals Reachability Scoring & Events / reachability-smoke (push) Has been cancelled
AOC Guard CI / aoc-guard (push) Has been cancelled
Concelier Attestation Tests / attestation-tests (push) Has been cancelled
cryptopro-linux-csp / build-and-test (push) Has been cancelled
Scanner Analyzers / Validate Test Fixtures (push) Has been cancelled
Signals CI & Image / signals-ci (push) Has been cancelled
sm-remote-ci / build-and-test (push) Has been cancelled
Findings Ledger CI / generate-manifest (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Scanner Analyzers / Build Analyzers (push) Has been cancelled
Scanner Analyzers / Test Language Analyzers (push) Has been cancelled
Scanner Analyzers / Verify Deterministic Output (push) Has been cancelled
Signals Reachability Scoring & Events / sign-and-upload (push) Has been cancelled
1.5 KiB
1.5 KiB
Dataset Safety & Provenance Checklist (RD1–RD10)
Version: 1.0.1 · Date: 2025-12-03
- PII/secret scrub: no tokens/URLs; build/test logs redacted. Attested by DSSE when signing manifest.
- License compatibility: all cases authored in-repo under Apache-2.0; third-party snippets none. NOTICE up to date.
- Feed/tool lockfile: manifest.sample.json pins hashes for schemas, scorer, builder, and baseline submissions (when present).
- Published schemas/validators: truth/submission/coverage/trace + manifest schemas; validated via
tools/validate.pyandtools/verify_manifest.py. - Evidence bundles: coverage + traces + attestation + sbom recorded per case (sample manifest).
- Binary case recipe:
cases/**/build/build.shpinnedSOURCE_DATE_EPOCHand env templates underbenchmark/templates/determinism/. - Determinism CI:
ci/run-ci.sh+tools/verify_manifest.pyrun twice to compare hashes; Java track uses vendored Temurin 21 viatools/java/ensure_jdk.sh. - Signed baselines: baseline submissions may include DSSE path in manifest (not required for sample kit); rulepack hashes recorded separately.
- Submission policy: CLA/DSSE optional in sample; production kits require DSSE envelope recorded in
signatures. - Semantic versioning & changelog: see
benchmark/CHANGELOG.md; manifestversionmirrors dataset release. - Offline kit packaging:
tools/package_offline_kit.shproduces deterministic tarball with manifest + schemas + tools.