Commit Graph

706 Commits

Author SHA1 Message Date
pulse-triage[bot] bd146586e8 Make release continuity failures actionable
Change-source: pulse-maintainer
2026-08-31 21:20:30 +01:00
rcourtman 5754d924d7 Add rootful Docker secure-runtime qualification 2026-08-31 18:13:22 +01:00
pulse-triage[bot] da36bcd482 Keep subsystem lookup tests checkout-independent
Change-source: pulse-maintainer
2026-08-31 16:00:47 +01:00
rcourtman cdfcac5756 Refresh v6.4.2 final cutoff 2026-08-31 13:46:43 +01:00
pulse-triage[bot] 164b747e83 Make contract audit tests checkout-independent 2026-08-31 12:26:33 +01:00
rcourtman f47ac1f020 Define beta and RC release maturity 2026-08-31 11:42:03 +01:00
rcourtman 70c1d0a178 Authenticate RC artifacts before qualification 2026-08-31 09:49:41 +01:00
rcourtman 7650fdaba3 Wire secure runtime RC qualification 2026-08-31 01:50:48 +01:00
Richard Courtman d3884d64db Prepare v6.4.2 security patch 2026-08-31 01:03:09 +01:00
pulse-triage[bot] eb0d17c282 Restore trustworthy governance signals 2026-08-31 00:55:44 +01:00
Richard Courtman 08f7c5f0d5 Harden secure agent runtime boundaries 2026-08-31 00:06:24 +01:00
Richard Courtman a8bc2e044b Qualify helper-backed agent update recovery 2026-08-30 21:54:46 +01:00
pulse-triage[bot] e094a55b45 Integrate typed helper container summaries 2026-08-30 21:29:11 +01:00
pulse-triage[bot] cb079c9de0 Publish portable candidate build provenance 2026-08-30 20:34:04 +01:00
Richard Courtman b369dc5410 Accept canonical schema-v4 runtime evidence 2026-08-30 18:58:49 +01:00
Richard Courtman 77afff4f60 Bind action runner to enrolled agent identity 2026-08-30 18:49:12 +01:00
Richard Courtman 65bec55229 Exercise pending runner activation in systemd lab 2026-08-30 18:24:29 +01:00
Richard Courtman 98e8f86806 Harden secure runtime qualification provenance 2026-08-30 18:17:36 +01:00
pulse-triage[bot] d732b5a9e8 Restore scoped governance audit signal 2026-08-30 17:01:44 +01:00
Pulse Test 7e92ac8118 Harden secure runtime separation boundaries 2026-08-30 14:26:01 +01:00
pulse-triage[bot] 7d9e77ff32 Continuously verify stable container aliases 2026-08-30 13:55:41 +01:00
pulse-triage[bot] 9393b710da Preflight immutable release publication 2026-08-30 12:55:51 +01:00
Pulse Test 5be6706428 Verify secure runtime qualification provenance 2026-08-30 09:46:29 +01:00
pulse-triage[bot] 2fca8c957b Authenticate published release sidecars 2026-08-30 09:38:23 +01:00
pulse-triage[bot] f70da05467 Bind Helm delivery to release provenance 2026-08-30 07:34:56 +01:00
pulse-triage[bot] e66f6a26f7 Fail closed when installing MCP binaries
Verify the signed release checksum manifest against Pulse's pinned SSH key before either MCP installer accepts a downloaded binary. Remove the unsigned bypass and require one exact digest entry.

Include bare Unix MCP executables in release checksum/signature assembly, cover unavailable, invalid, ambiguous, mismatched, and successful evidence paths with executable regression tests, and enforce MCP installer pins against the configured release key.
2026-08-30 05:11:55 +01:00
pulse-triage[bot] d8986c139a Enforce workflow data trust boundaries
Contract-Neutral: Moves workflow expressions into environment data flow without changing deployment interfaces or behavior.
2026-08-30 04:56:34 +01:00
pulse-triage[bot] ac2a2fe020 Complete release and helper download safeguards 2026-08-30 01:51:58 +01:00
pulse-triage[bot] 718de25b2b Bind release activation to trusted provenance 2026-08-30 01:51:58 +01:00
Pulse Test d607d5cf46 Separate agent remediation runtime 2026-08-29 23:48:28 +01:00
pulse-triage[bot] e67e4a7c5f Bind container promotion to attested digests 2026-08-29 22:56:12 +01:00
Pulse Test 6d4ee48000 Add typed agent privilege helper 2026-08-29 22:51:58 +01:00
pulse-triage[bot] 7e7fb53911 Gate release publication on immutable setting 2026-08-29 22:41:04 +01:00
pulse-triage[bot] 4d60d679f0 Bind activation marker to release attestation 2026-08-29 22:23:54 +01:00
pulse-triage[bot] 5926b4dc38 Align release integrity proof fixture 2026-08-29 20:03:39 +01:00
pulse-triage[bot] 1d170de364 Require immutable attested releases 2026-08-29 19:59:04 +01:00
pulse-triage[bot] 3e66f042a5 Document shipped availability probe coverage
Change-source: pulse-maintainer
2026-08-29 18:21:50 +01:00
pulse-triage[bot] 523bb3f705 Synchronize monitoring governance fixture
Include the newly accepted reload proof in the canonical guard's exact monitoring-runtime expectation.

Change-source: pulse-maintainer
2026-08-29 15:03:25 +01:00
pulse-triage[bot] 88da3e05c9 Document persistent agent log level control
Change-source: pulse-maintainer
2026-08-29 13:55:32 +01:00
pulse-triage[bot] ba73a5474e Keep published release validation non-destructive 2026-08-29 10:27:08 +01:00
pulse-triage[bot] 505dcd571f Keep server rollback guidance executable 2026-08-29 10:15:45 +01:00
pulse-triage[bot] 5981892dfe Bootstrap absent promotion lease ref 2026-08-29 04:15:50 +01:00
pulse-triage[bot] 0443bcf174 Use semantic demo connection status 2026-08-29 04:02:06 +01:00
pulse-triage[bot] 2c6eb9a58d Clear retired demo alert replay sources 2026-08-29 03:57:50 +01:00
pulse-triage[bot] 5686069d6e Reset poisoned demo incident replay 2026-08-29 03:53:34 +01:00
Richard Courtman db0145b2b9 Bound legacy demo history startup 2026-08-29 03:47:09 +01:00
pulse-triage[bot] 2bf37a58c7 Capture blocked demo startup stack 2026-08-29 03:46:48 +01:00
pulse-triage[bot] 0d5b1202b5 Disable dev metrics backfill on stable demo 2026-08-29 03:41:44 +01:00
Richard Courtman 7255e44f57 Retain demo recovery diagnostics 2026-08-29 03:33:03 +01:00
Richard Courtman c006b15871 Require proven large-demo startup 2026-08-29 03:28:50 +01:00