- Introduced a new VEX compact fixture for testing purposes. - Implemented `verify_export.py` script to validate Findings Ledger exports, ensuring deterministic ordering and applying redaction manifests. - Added a lightweight stub `HarnessRunner` for unit tests to validate ledger hashing expectations. - Documented tasks related to the Mirror Creator. - Created models for entropy signals and implemented the `EntropyPenaltyCalculator` to compute penalties based on scanner outputs. - Developed unit tests for `EntropyPenaltyCalculator` to ensure correct penalty calculations and handling of edge cases. - Added tests for symbol ID normalization in the reachability scanner. - Enhanced console status service with comprehensive unit tests for connection handling and error recovery. - Included Cosign tool version 2.6.0 with checksums for various platforms.
Mirror signing helpers
make-thin-v1.sh: builds thin bundle v1, computes checksums, emits bundle meta (offline/rekor/mirror gaps), optional DSSE+TUF signing whenSIGN_KEYis set, and runs verifier.sign_thin_bundle.py: signs manifest (DSSE), bundle meta (DSSE), and root/targets/snapshot/timestamp JSON using an Ed25519 PEM key.verify_thin_bundle.py: checks SHA256 sidecars, manifest schema, tar determinism, required layers, optional bundle meta and DSSE signatures; accepts--bundle-meta,--pubkey,--tenant,--environment.ci-sign.sh: CI wrapper. SetMIRROR_SIGN_KEY_B64(base64-encoded Ed25519 PEM) and run; it builds, signs, and verifies in one step, emittingmilestone.jsonwith manifest/tar/bundle hashes.verify_oci_layout.py: validates OCI layout/index/manifest and blob digests whenOCI=1is used.
Artifacts live under out/mirror/thin/.