pulse-triage[bot]
9a6a5811a7
ci: qualify setup-node v7 consumer contracts
...
The standalone setup-node proposal lacked lifecycle and deployment evidence. Preserve Node 24, explicit cache controls and native Windows proof steps while upgrading the immutable action revision; add consumer regression coverage for the removed dummy auth-token assumption. Keep grouped signing and deployment action upgrades separate.
Change-source: pulse-maintainer
2026-09-09 19:29:17 +01:00
rcourtman
ab562c82aa
Encode the release source branch through the shared output helper
...
The branch is validated by the snapshot guard, but its transfer between
workflow steps must also use the canonical GitHub command-file encoder.
Keep the source binding unchanged and satisfy the workflow trust audit.
Validation: all 41 workflow trust tests and five snapshot tests pass.
Contract-Neutral: Encode the already-validated release branch with the shared GitHub command-file helper without changing source identity or release authority
2026-09-07 19:38:48 +01:00
rcourtman
b64709e7b7
Publish reviewed release snapshots independently of branch tips
...
Continuous development must not change the source of an admitted release.
Allow the workflow to run at the qualified preparation PR head after its
normal merge, verifying exact source and workflow identity, canonical PR
provenance, and ancestry in the governed release line. Later branch commits
remain outside that release. Document the immutable-candidate contract and
verify source workflow compatibility before qualification.
Validation: snapshot identity and workflow contract tests passed, including
wrong-head, wrong-base, fork, unmerged and unbound dispatch rejection. The
existing release workflow promotion policy test also passed.
2026-09-07 19:30:27 +01:00
pulse-triage[bot]
457aa90458
Keep release workflows free of implicit trust inputs
...
Remove the pull-request secret exception, drop inert E2E secret references, and disable setup-node caches at release trust boundaries. Document the exact metadata-only privileged trigger exception.
Change-source: pulse-maintainer
2026-09-04 07:30:35 +01:00
pulse-triage[bot]
f503b13442
Bind release dispatches to the admitted commit
...
A workflow dispatch by branch can resolve after that branch moves, allowing an unreviewed tip to enter the release pipeline. Require every publishing dispatch to name its expected source SHA and make the workflow reject a different source or workflow commit before checkout.
Change-source: pulse-maintainer
(cherry picked from commit a461fc9c0a )
2026-09-02 02:28:14 +01:00
pulse-triage[bot]
f61815839f
Keep unsigned caches out of privileged workflows
...
Change-source: pulse-maintainer
2026-09-01 19:29:37 +01:00
pulse-triage[bot]
de41ea1883
Preserve workflow taint across branches
...
Change-source: pulse-maintainer
2026-09-01 17:34:30 +01:00
pulse-triage[bot]
4f7a3d0006
Close runner output alias bypasses
...
Change-source: pulse-maintainer
2026-09-01 16:54:07 +01:00
pulse-triage[bot]
c55db584c1
Harden GitHub command file data boundaries
...
Change-source: pulse-maintainer
2026-09-01 16:32:15 +01:00
pulse-triage[bot]
1ef5618190
Verify exact release activation bytes
...
Change-source: pulse-maintainer
2026-09-01 13:29:06 +01:00
pulse-triage[bot]
faf69f76e6
Keep workflow outputs out of generated shell
...
Change-source: pulse-maintainer
2026-09-01 10:16:41 +01:00
pulse-triage[bot]
ba727edf12
Refresh trusted checkout action
...
Change-source: pulse-maintainer
2026-09-01 02:31:08 +01:00
rcourtman
83cc5e5642
Give stable backend qualification full completion headroom
2026-08-31 19:05:32 +01:00
rcourtman
5754d924d7
Add rootful Docker secure-runtime qualification
2026-08-31 18:13:22 +01:00
pulse-triage[bot]
69cbe5f3b8
Enforce protected GitHub checkout baseline
2026-08-31 13:21:25 +01:00
rcourtman
f47ac1f020
Define beta and RC release maturity
2026-08-31 11:42:03 +01:00
pulse-triage[bot]
fda955627f
Bound GitHub Actions job runtimes
2026-08-31 02:00:09 +01:00
rcourtman
7650fdaba3
Wire secure runtime RC qualification
2026-08-31 01:50:48 +01:00
pulse-triage[bot]
cb079c9de0
Publish portable candidate build provenance
2026-08-30 20:34:04 +01:00
pulse-triage[bot]
9393b710da
Preflight immutable release publication
2026-08-30 12:55:51 +01:00
pulse-triage[bot]
2fca8c957b
Authenticate published release sidecars
2026-08-30 09:38:23 +01:00
pulse-triage[bot]
f70da05467
Bind Helm delivery to release provenance
2026-08-30 07:34:56 +01:00
pulse-triage[bot]
0d32dac16e
Keep release toolchains within support
2026-08-30 06:40:25 +01:00
pulse-triage[bot]
a2bfadba7b
Enforce workflow execution trust boundaries
2026-08-30 04:44:25 +01:00
Pulse Test
d607d5cf46
Separate agent remediation runtime
2026-08-29 23:48:28 +01:00
pulse-triage[bot]
e67e4a7c5f
Bind container promotion to attested digests
2026-08-29 22:56:12 +01:00
Pulse Test
6d4ee48000
Add typed agent privilege helper
2026-08-29 22:51:58 +01:00
pulse-triage[bot]
7e7fb53911
Gate release publication on immutable setting
2026-08-29 22:41:04 +01:00
pulse-triage[bot]
1d170de364
Require immutable attested releases
2026-08-29 19:59:04 +01:00
Richard Courtman
58b07ef36c
Serialize Docker staging after draft recovery
2026-08-29 01:29:17 +01:00
Pulse Test
0dc2c8c16d
Require prerelease observation windows
2026-08-28 20:39:32 +01:00
Pulse Test
a1ae0fa07f
fix(release): require visual selection evidence
2026-08-28 20:11:04 +01:00
Pulse Test
354c1e6ffd
feat(release): add visual changelog comparisons
2026-08-28 11:29:44 +01:00
pulse-triage[bot]
94ccf96bad
Accept qualified recovered release activation
2026-08-28 03:51:26 +01:00
Richard Courtman
7324867556
Harden release backend cold-run qualification
2026-08-28 03:36:33 +01:00
Richard Courtman
827017e196
Prepare v6.4.0-rc.10 release
2026-08-28 02:23:24 +01:00
pulse-triage[bot]
99a4ea45cb
Govern rc.9 release timeout recovery
2026-08-28 02:10:07 +01:00
pulse-triage[bot]
a65cd94c53
Give release backend tests timeout headroom
2026-08-28 02:07:19 +01:00
rcourtman
ee22a969d3
Bind container qualification to caller commit
...
Change-source: pulse-maintainer
2026-08-26 03:36:46 +01:00
rcourtman
9ff5dfb4d4
Disable Windows signing until SignPath is ready
2026-08-25 22:24:07 +01:00
Richard Courtman
1c76a7cbdc
Enforce customer-facing release notes
2026-08-25 17:13:07 +01:00
rcourtman
6869612c66
Isolate PC compilation from SignPath workflow
2026-08-23 15:02:33 +01:00
rcourtman
567eca2572
Harden stable release convergence
2026-08-23 14:21:09 +01:00
rcourtman
c1d0aaa0d5
Approve v6.3.1 unsigned Windows exception
2026-08-23 12:02:53 +01:00
rcourtman
34ae5c98f9
Fix SignPath release provenance
2026-08-23 11:39:21 +01:00
rcourtman
b88e05d1ce
Prepare v6.3.0 stable release
2026-08-22 10:35:27 +01:00
rcourtman
9ef94418e8
Accelerate release convergence on PVE
2026-08-21 20:41:04 +01:00
rcourtman
e5389e2130
Parallelize inert release artifact staging
2026-08-21 18:08:22 +01:00
rcourtman
418402bf9e
Use complete PVE release worktree
2026-08-21 16:19:11 +01:00
rcourtman
d45ecd9a24
Include release helpers in PVE checkout
2026-08-21 16:14:21 +01:00