Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
- Introduced a blueprint for explainable quiet alerts, detailing phases for SBOM, VEX readiness, and attestations. - Developed a roadmap for deterministic diff-aware rescans, enhancing scanner speed and efficiency. - Implemented a hash-based SBOM layer cache to optimize container scans by reusing previous results. - Created a multi-runtime reachability corpus to validate function-level reachability across various programming languages. - Proposed a stable SBOM model using SPDX 3.0.1 for persistence and CycloneDX 1.6 for interchange. - Established a validation plan for quiet scans, focusing on provenance and CI integration. - Documented guidelines for the Findings Ledger module, outlining roles, execution rules, and testing protocols.
1.9 KiB
1.9 KiB
2025-11-12 – Notifications Attestation Template Suite
Summary
- Introduced the canonical
tmpl-attest-*template family covering verification failures, expiring attestations, key rotations, and transparency anomalies. - Synchronized overview, rules, and architecture docs so operators, rule authors, and implementers share the same guidance for attestation-triggered notifications.
- Captured Offline Kit expectations and helper usage so the upcoming NOTIFY-ATTEST-74-002 wiring work has stable artefacts to reference.
Details
docs/notifications/templates.mdnow includes Section 7 with required fields, helper references, Slack/Email/Webhook samples, and Offline Kit packaging notes for the attestation lifecycle templates.- Baseline exported templates for each required channel now live under
offline/notifier/templates/attestation/*.template.jsonso Offline Kit consumers inherit the canonical payloads immediately. docs/notifications/overview.mdhighlights that template capabilities include the attestation suite and reiterates determinism requirements around thetmpl-attest-*keys.docs/notifications/rules.mdadds Section 4.0, mandating the new template keys forattestor.*andauthority.keys.*events so rules do not drift.docs/notifications/architecture.mdreferences the template suite inside the rendering pipeline description, reminding service owners to populate attestation context fields.- Sprint trackers (
SPRINT_170_notifications_telemetry.md,SPRINT_171_notifier_i.md) note the documentation progress for NOTIFY-ATTEST-74-001.
Follow-ups
- Finalise the attestation event schema on 2025‑11‑13 so the documented templates can be localised and promoted to Offline Kits.
- Export the new templates into Offline Kit manifests (
offline/notifier/templates/attestation/) once schemas lock. - Update rule/controller defaults so attestation-triggered rules reference the documented template keys by default.