Commit Graph

1440 Commits

Author SHA1 Message Date
Richard Courtman d3884d64db Prepare v6.4.2 security patch 2026-08-31 01:03:09 +01:00
pulse-triage[bot] eb0d17c282 Restore trustworthy governance signals 2026-08-31 00:55:44 +01:00
Richard Courtman 22fd662fb7 Match secure runtime revoke protocol 2026-08-31 00:33:49 +01:00
Richard Courtman b1028a23af Align secure runtime lifecycle fixture auth 2026-08-31 00:22:22 +01:00
Richard Courtman f87308fb63 Fix secure runtime qualification admission 2026-08-31 00:15:43 +01:00
Richard Courtman 08f7c5f0d5 Harden secure agent runtime boundaries 2026-08-31 00:06:24 +01:00
pulse-triage[bot] 47c1cee895 Enforce least-privilege job tokens 2026-08-30 22:11:40 +01:00
Richard Courtman a8bc2e044b Qualify helper-backed agent update recovery 2026-08-30 21:54:46 +01:00
pulse-triage[bot] e094a55b45 Integrate typed helper container summaries 2026-08-30 21:29:11 +01:00
pulse-triage[bot] cb079c9de0 Publish portable candidate build provenance 2026-08-30 20:34:04 +01:00
Richard Courtman defc24af83 Bind receipt completion to final evidence event 2026-08-30 19:06:37 +01:00
Richard Courtman b369dc5410 Accept canonical schema-v4 runtime evidence 2026-08-30 18:58:49 +01:00
Richard Courtman 77afff4f60 Bind action runner to enrolled agent identity 2026-08-30 18:49:12 +01:00
Richard Courtman 65bec55229 Exercise pending runner activation in systemd lab 2026-08-30 18:24:29 +01:00
Richard Courtman 98e8f86806 Harden secure runtime qualification provenance 2026-08-30 18:17:36 +01:00
Richard Courtman 770733fc92 Make action runner rotation activation-safe 2026-08-30 18:00:33 +01:00
pulse-triage[bot] d732b5a9e8 Restore scoped governance audit signal 2026-08-30 17:01:44 +01:00
pulse-triage[bot] 323da54067 Support agent retargeting after server moves 2026-08-30 16:17:15 +01:00
pulse-triage[bot] c3faa48973 Watch stable release locks continuously 2026-08-30 16:17:15 +01:00
Pulse Test 87a37e8d2f Publish secure runtime qualification matrix 2026-08-30 15:15:36 +01:00
pulse-triage[bot] a0dfdadc5e Close workflow trust policy gaps 2026-08-30 15:06:00 +01:00
pulse-triage[bot] 21007a8662 Isolate private governance from pull requests 2026-08-30 15:02:41 +01:00
Pulse Test b2543c5c6e Distinguish receipt paths from credentials 2026-08-30 14:50:39 +01:00
Pulse Test 9a9c03c1b1 Prepare pristine apt cache fixture 2026-08-30 14:45:13 +01:00
Pulse Test 7e92ac8118 Harden secure runtime separation boundaries 2026-08-30 14:26:01 +01:00
pulse-triage[bot] 7d9e77ff32 Continuously verify stable container aliases 2026-08-30 13:55:41 +01:00
pulse-triage[bot] 8724f6b9e5 Continuously verify stable release delivery 2026-08-30 13:10:22 +01:00
pulse-triage[bot] 9393b710da Preflight immutable release publication 2026-08-30 12:55:51 +01:00
Pulse Test 5be6706428 Verify secure runtime qualification provenance 2026-08-30 09:46:29 +01:00
pulse-triage[bot] 2fca8c957b Authenticate published release sidecars 2026-08-30 09:38:23 +01:00
Pulse Test cb843e37e8 Qualify separate action runner lifecycle 2026-08-30 09:07:27 +01:00
pulse-triage[bot] f70da05467 Bind Helm delivery to release provenance 2026-08-30 07:34:56 +01:00
pulse-triage[bot] 0d32dac16e Keep release toolchains within support 2026-08-30 06:40:25 +01:00
pulse-triage[bot] e66f6a26f7 Fail closed when installing MCP binaries
Verify the signed release checksum manifest against Pulse's pinned SSH key before either MCP installer accepts a downloaded binary. Remove the unsigned bypass and require one exact digest entry.

Include bare Unix MCP executables in release checksum/signature assembly, cover unavailable, invalid, ambiguous, mismatched, and successful evidence paths with executable regression tests, and enforce MCP installer pins against the configured release key.
2026-08-30 05:11:55 +01:00
pulse-triage[bot] d8986c139a Enforce workflow data trust boundaries
Contract-Neutral: Moves workflow expressions into environment data flow without changing deployment interfaces or behavior.
2026-08-30 04:56:34 +01:00
pulse-triage[bot] a2bfadba7b Enforce workflow execution trust boundaries 2026-08-30 04:44:25 +01:00
pulse-triage[bot] f9ffbf701a Strengthen dependency maintenance contracts 2026-08-30 04:05:02 +01:00
pulse-triage[bot] 560c2de026 Automate dependency trust maintenance 2026-08-30 04:02:27 +01:00
pulse-triage[bot] ac2a2fe020 Complete release and helper download safeguards 2026-08-30 01:51:58 +01:00
pulse-triage[bot] 718de25b2b Bind release activation to trusted provenance 2026-08-30 01:51:58 +01:00
Pulse Test d06ffc233d Harden secure agent runtime transitions 2026-08-30 01:41:57 +01:00
Pulse Test d607d5cf46 Separate agent remediation runtime 2026-08-29 23:48:28 +01:00
pulse-triage[bot] e67e4a7c5f Bind container promotion to attested digests 2026-08-29 22:56:12 +01:00
Pulse Test 6d4ee48000 Add typed agent privilege helper 2026-08-29 22:51:58 +01:00
pulse-triage[bot] 7e7fb53911 Gate release publication on immutable setting 2026-08-29 22:41:04 +01:00
pulse-triage[bot] 4d60d679f0 Bind activation marker to release attestation 2026-08-29 22:23:54 +01:00
Pulse Test a966264bb1 Contain agent command authority 2026-08-29 22:12:41 +01:00
pulse-triage[bot] 5926b4dc38 Align release integrity proof fixture 2026-08-29 20:03:39 +01:00
pulse-triage[bot] 1d170de364 Require immutable attested releases 2026-08-29 19:59:04 +01:00
pulse-triage[bot] 3e66f042a5 Document shipped availability probe coverage
Change-source: pulse-maintainer
2026-08-29 18:21:50 +01:00