Some checks failed
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Manifest Integrity / Audit SHA256SUMS Files (push) Has been cancelled
Manifest Integrity / Validate Schema Integrity (push) Has been cancelled
Manifest Integrity / Validate Contract Documents (push) Has been cancelled
Manifest Integrity / Validate Pack Fixtures (push) Has been cancelled
Manifest Integrity / Verify Merkle Roots (push) Has been cancelled
Scanner Analyzers / Build Analyzers (push) Has been cancelled
Scanner Analyzers / Discover Analyzers (push) Has been cancelled
Scanner Analyzers / Test Language Analyzers (push) Has been cancelled
Scanner Analyzers / Validate Test Fixtures (push) Has been cancelled
Scanner Analyzers / Verify Deterministic Output (push) Has been cancelled
Signals CI & Image / signals-ci (push) Has been cancelled
Concelier Attestation Tests / attestation-tests (push) Has been cancelled
Policy Lint & Smoke / policy-lint (push) Has been cancelled
Export Center CI / export-ci (push) Has been cancelled
Notify Smoke Test / Notify Unit Tests (push) Has been cancelled
Notify Smoke Test / Notifier Service Tests (push) Has been cancelled
Notify Smoke Test / Notification Smoke Test (push) Has been cancelled
- Introduced `NativeTestBase` class for ELF, PE, and Mach-O binary parsing helpers and assertions. - Created `TestCryptoFactory` for SM2 cryptographic provider setup and key generation. - Implemented `Sm2SigningTests` to validate signing functionality with environment gate checks. - Developed console export service and store with comprehensive unit tests for export status management.
1.5 KiB
1.5 KiB
DSSE Revision Decision
Decision ID: DECISION-MIRROR-001 Status: DEFAULT-APPROVED Effective Date: 2025-12-06 48h Window Started: 2025-12-06T00:00:00Z
Decision
The Mirror bundle DSSE envelope format follows the in-toto v1.0 specification with StellaOps extensions for offline verification.
Rationale
- in-toto v1.0 is the industry standard for software supply chain attestations
- DSSE (Dead Simple Signing Envelope) provides a clean JSON wrapper
- Existing tooling (
cosign,rekor) supports this format - Aligns with Evidence Locker DSSE patterns already implemented
Specification
{
"payloadType": "application/vnd.in-toto+json",
"payload": "<base64-encoded-in-toto-statement>",
"signatures": [
{
"keyid": "<key-id>",
"sig": "<base64-signature>"
}
]
}
StellaOps Extensions
_stellaops.revision: Bundle revision number_stellaops.timestamp: ISO-8601 UTC timestamp_stellaops.merkleRoot: SHA-256 Merkle root of bundle contents
Impact
- Tasks unblocked: ~5
- Sprint files affected: SPRINT_0150_mirror_dsse
Reversibility
To change the DSSE format:
- Propose new format in
docs/modules/mirror/dsse-proposal.md - Get Security Guild sign-off
- Update all affected sprint files
- Ensure backward compatibility for existing bundles