183 Commits

Author SHA1 Message Date
pulse-triage[bot] 9a6a5811a7 ci: qualify setup-node v7 consumer contracts
The standalone setup-node proposal lacked lifecycle and deployment evidence. Preserve Node 24, explicit cache controls and native Windows proof steps while upgrading the immutable action revision; add consumer regression coverage for the removed dummy auth-token assumption. Keep grouped signing and deployment action upgrades separate.

Change-source: pulse-maintainer
2026-09-09 19:29:17 +01:00
rcourtman ab562c82aa Encode the release source branch through the shared output helper
The branch is validated by the snapshot guard, but its transfer between
workflow steps must also use the canonical GitHub command-file encoder.
Keep the source binding unchanged and satisfy the workflow trust audit.

Validation: all 41 workflow trust tests and five snapshot tests pass.
Contract-Neutral: Encode the already-validated release branch with the shared GitHub command-file helper without changing source identity or release authority
2026-09-07 19:38:48 +01:00
rcourtman b64709e7b7 Publish reviewed release snapshots independently of branch tips
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.

Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
2026-09-07 19:30:27 +01:00
pulse-triage[bot] 457aa90458 Keep release workflows free of implicit trust inputs
Remove the pull-request secret exception, drop inert E2E secret references, and disable setup-node caches at release trust boundaries. Document the exact metadata-only privileged trigger exception.

Change-source: pulse-maintainer
2026-09-04 07:30:35 +01:00
pulse-triage[bot] f503b13442 Bind release dispatches to the admitted commit
A workflow dispatch by branch can resolve after that branch moves, allowing an unreviewed tip to enter the release pipeline. Require every publishing dispatch to name its expected source SHA and make the workflow reject a different source or workflow commit before checkout.

Change-source: pulse-maintainer
(cherry picked from commit a461fc9c0a)
2026-09-02 02:28:14 +01:00
pulse-triage[bot] f61815839f Keep unsigned caches out of privileged workflows
Change-source: pulse-maintainer
2026-09-01 19:29:37 +01:00
pulse-triage[bot] de41ea1883 Preserve workflow taint across branches
Change-source: pulse-maintainer
2026-09-01 17:34:30 +01:00
pulse-triage[bot] 4f7a3d0006 Close runner output alias bypasses
Change-source: pulse-maintainer
2026-09-01 16:54:07 +01:00
pulse-triage[bot] c55db584c1 Harden GitHub command file data boundaries
Change-source: pulse-maintainer
2026-09-01 16:32:15 +01:00
pulse-triage[bot] 1ef5618190 Verify exact release activation bytes
Change-source: pulse-maintainer
2026-09-01 13:29:06 +01:00
pulse-triage[bot] faf69f76e6 Keep workflow outputs out of generated shell
Change-source: pulse-maintainer
2026-09-01 10:16:41 +01:00
pulse-triage[bot] ba727edf12 Refresh trusted checkout action
Change-source: pulse-maintainer
2026-09-01 02:31:08 +01:00
rcourtman 83cc5e5642 Give stable backend qualification full completion headroom 2026-08-31 19:05:32 +01:00
rcourtman 5754d924d7 Add rootful Docker secure-runtime qualification 2026-08-31 18:13:22 +01:00
pulse-triage[bot] 69cbe5f3b8 Enforce protected GitHub checkout baseline 2026-08-31 13:21:25 +01:00
rcourtman f47ac1f020 Define beta and RC release maturity 2026-08-31 11:42:03 +01:00
pulse-triage[bot] fda955627f Bound GitHub Actions job runtimes 2026-08-31 02:00:09 +01:00
rcourtman 7650fdaba3 Wire secure runtime RC qualification 2026-08-31 01:50:48 +01:00
pulse-triage[bot] cb079c9de0 Publish portable candidate build provenance 2026-08-30 20:34:04 +01:00
pulse-triage[bot] 9393b710da Preflight immutable release publication 2026-08-30 12:55:51 +01:00
pulse-triage[bot] 2fca8c957b Authenticate published release sidecars 2026-08-30 09:38:23 +01:00
pulse-triage[bot] f70da05467 Bind Helm delivery to release provenance 2026-08-30 07:34:56 +01:00
pulse-triage[bot] 0d32dac16e Keep release toolchains within support 2026-08-30 06:40:25 +01:00
pulse-triage[bot] a2bfadba7b Enforce workflow execution trust boundaries 2026-08-30 04:44:25 +01:00
Pulse Test d607d5cf46 Separate agent remediation runtime 2026-08-29 23:48:28 +01:00
pulse-triage[bot] e67e4a7c5f Bind container promotion to attested digests 2026-08-29 22:56:12 +01:00
Pulse Test 6d4ee48000 Add typed agent privilege helper 2026-08-29 22:51:58 +01:00
pulse-triage[bot] 7e7fb53911 Gate release publication on immutable setting 2026-08-29 22:41:04 +01:00
pulse-triage[bot] 1d170de364 Require immutable attested releases 2026-08-29 19:59:04 +01:00
Richard Courtman 58b07ef36c Serialize Docker staging after draft recovery 2026-08-29 01:29:17 +01:00
Pulse Test 0dc2c8c16d Require prerelease observation windows 2026-08-28 20:39:32 +01:00
Pulse Test a1ae0fa07f fix(release): require visual selection evidence 2026-08-28 20:11:04 +01:00
Pulse Test 354c1e6ffd feat(release): add visual changelog comparisons 2026-08-28 11:29:44 +01:00
pulse-triage[bot] 94ccf96bad Accept qualified recovered release activation 2026-08-28 03:51:26 +01:00
Richard Courtman 7324867556 Harden release backend cold-run qualification 2026-08-28 03:36:33 +01:00
Richard Courtman 827017e196 Prepare v6.4.0-rc.10 release 2026-08-28 02:23:24 +01:00
pulse-triage[bot] 99a4ea45cb Govern rc.9 release timeout recovery 2026-08-28 02:10:07 +01:00
pulse-triage[bot] a65cd94c53 Give release backend tests timeout headroom 2026-08-28 02:07:19 +01:00
rcourtman ee22a969d3 Bind container qualification to caller commit
Change-source: pulse-maintainer
2026-08-26 03:36:46 +01:00
rcourtman 9ff5dfb4d4 Disable Windows signing until SignPath is ready 2026-08-25 22:24:07 +01:00
Richard Courtman 1c76a7cbdc Enforce customer-facing release notes 2026-08-25 17:13:07 +01:00
rcourtman 6869612c66 Isolate PC compilation from SignPath workflow 2026-08-23 15:02:33 +01:00
rcourtman 567eca2572 Harden stable release convergence 2026-08-23 14:21:09 +01:00
rcourtman c1d0aaa0d5 Approve v6.3.1 unsigned Windows exception 2026-08-23 12:02:53 +01:00
rcourtman 34ae5c98f9 Fix SignPath release provenance 2026-08-23 11:39:21 +01:00
rcourtman b88e05d1ce Prepare v6.3.0 stable release 2026-08-22 10:35:27 +01:00
rcourtman 9ef94418e8 Accelerate release convergence on PVE 2026-08-21 20:41:04 +01:00
rcourtman e5389e2130 Parallelize inert release artifact staging 2026-08-21 18:08:22 +01:00
rcourtman 418402bf9e Use complete PVE release worktree 2026-08-21 16:19:11 +01:00
rcourtman d45ecd9a24 Include release helpers in PVE checkout 2026-08-21 16:14:21 +01:00