Commit Graph

412 Commits

Author SHA1 Message Date
pulse-triage[bot] f12c4007ab Serialize stable demo operations
Change-source: pulse-maintainer
2026-09-01 08:47:52 +01:00
pulse-triage[bot] ba727edf12 Refresh trusted checkout action
Change-source: pulse-maintainer
2026-09-01 02:31:08 +01:00
pulse-triage[bot] e1bce8b77f Build release payloads on ephemeral runners
Change-source: pulse-maintainer
2026-09-01 01:41:09 +01:00
rcourtman f967857928 Harden secure agent recovery transports 2026-08-31 23:12:00 +01:00
rcourtman 2aece859a5 Harden safe rootless runtime recovery 2026-08-31 22:17:07 +01:00
pulse-triage[bot] bd146586e8 Make release continuity failures actionable
Change-source: pulse-maintainer
2026-08-31 21:20:30 +01:00
rcourtman 83cc5e5642 Give stable backend qualification full completion headroom 2026-08-31 19:05:32 +01:00
rcourtman 5754d924d7 Add rootful Docker secure-runtime qualification 2026-08-31 18:13:22 +01:00
rcourtman ed6f429674 Make action runner authority state crash-safe 2026-08-31 17:34:30 +01:00
pulse-triage[bot] 69cbe5f3b8 Enforce protected GitHub checkout baseline 2026-08-31 13:21:25 +01:00
rcourtman ee881d4849 Refresh v6.4.2 release cutoff 2026-08-31 12:14:12 +01:00
rcourtman 2ddd12cb31 Repair v6.4.2 Helm provenance 2026-08-31 11:59:11 +01:00
pulse-triage[bot] d5945f824d Preserve Pulse severity in systemd journal 2026-08-31 11:46:51 +01:00
rcourtman f47ac1f020 Define beta and RC release maturity 2026-08-31 11:42:03 +01:00
rcourtman 70c1d0a178 Authenticate RC artifacts before qualification 2026-08-31 09:49:41 +01:00
Richard Courtman da62890d82 Refresh v6.4.2 release packet 2026-08-31 09:45:27 +01:00
Richard Courtman 2ff027a743 Bind release candidate version explicitly 2026-08-31 09:37:28 +01:00
pulse-triage[bot] 240adaa5e4 Authenticate every published installer 2026-08-31 04:55:15 +01:00
pulse-triage[bot] 445ebacf24 Restore delivery qualification trust
Harden release workflow input transport and make native lifecycle proof honor each platform security boundary. Refresh stale telemetry and delivery qualifications.

Contract-Neutral: Formatting-only catalog updates and browser-verified alert copy; release compiler and native lifecycle changes update their owning contracts.
2026-08-31 03:02:13 +01:00
rcourtman 7650fdaba3 Wire secure runtime RC qualification 2026-08-31 01:50:48 +01:00
Richard Courtman d3884d64db Prepare v6.4.2 security patch 2026-08-31 01:03:09 +01:00
pulse-triage[bot] eb0d17c282 Restore trustworthy governance signals 2026-08-31 00:55:44 +01:00
Richard Courtman 22fd662fb7 Match secure runtime revoke protocol 2026-08-31 00:33:49 +01:00
Richard Courtman b1028a23af Align secure runtime lifecycle fixture auth 2026-08-31 00:22:22 +01:00
Richard Courtman f87308fb63 Fix secure runtime qualification admission 2026-08-31 00:15:43 +01:00
Richard Courtman 08f7c5f0d5 Harden secure agent runtime boundaries 2026-08-31 00:06:24 +01:00
Richard Courtman a8bc2e044b Qualify helper-backed agent update recovery 2026-08-30 21:54:46 +01:00
pulse-triage[bot] e094a55b45 Integrate typed helper container summaries 2026-08-30 21:29:11 +01:00
pulse-triage[bot] cb079c9de0 Publish portable candidate build provenance 2026-08-30 20:34:04 +01:00
Richard Courtman defc24af83 Bind receipt completion to final evidence event 2026-08-30 19:06:37 +01:00
Richard Courtman b369dc5410 Accept canonical schema-v4 runtime evidence 2026-08-30 18:58:49 +01:00
Richard Courtman 77afff4f60 Bind action runner to enrolled agent identity 2026-08-30 18:49:12 +01:00
Richard Courtman 65bec55229 Exercise pending runner activation in systemd lab 2026-08-30 18:24:29 +01:00
Richard Courtman 98e8f86806 Harden secure runtime qualification provenance 2026-08-30 18:17:36 +01:00
Richard Courtman 770733fc92 Make action runner rotation activation-safe 2026-08-30 18:00:33 +01:00
pulse-triage[bot] 323da54067 Support agent retargeting after server moves 2026-08-30 16:17:15 +01:00
pulse-triage[bot] c3faa48973 Watch stable release locks continuously 2026-08-30 16:17:15 +01:00
Pulse Test 87a37e8d2f Publish secure runtime qualification matrix 2026-08-30 15:15:36 +01:00
Pulse Test b2543c5c6e Distinguish receipt paths from credentials 2026-08-30 14:50:39 +01:00
Pulse Test 9a9c03c1b1 Prepare pristine apt cache fixture 2026-08-30 14:45:13 +01:00
Pulse Test 7e92ac8118 Harden secure runtime separation boundaries 2026-08-30 14:26:01 +01:00
pulse-triage[bot] 7d9e77ff32 Continuously verify stable container aliases 2026-08-30 13:55:41 +01:00
pulse-triage[bot] 8724f6b9e5 Continuously verify stable release delivery 2026-08-30 13:10:22 +01:00
pulse-triage[bot] 9393b710da Preflight immutable release publication 2026-08-30 12:55:51 +01:00
pulse-triage[bot] 2fca8c957b Authenticate published release sidecars 2026-08-30 09:38:23 +01:00
Pulse Test cb843e37e8 Qualify separate action runner lifecycle 2026-08-30 09:07:27 +01:00
pulse-triage[bot] f70da05467 Bind Helm delivery to release provenance 2026-08-30 07:34:56 +01:00
pulse-triage[bot] 0d32dac16e Keep release toolchains within support 2026-08-30 06:40:25 +01:00
pulse-triage[bot] e66f6a26f7 Fail closed when installing MCP binaries
Verify the signed release checksum manifest against Pulse's pinned SSH key before either MCP installer accepts a downloaded binary. Remove the unsigned bypass and require one exact digest entry.

Include bare Unix MCP executables in release checksum/signature assembly, cover unavailable, invalid, ambiguous, mismatched, and successful evidence paths with executable regression tests, and enforce MCP installer pins against the configured release key.
2026-08-30 05:11:55 +01:00
pulse-triage[bot] f9ffbf701a Strengthen dependency maintenance contracts 2026-08-30 04:05:02 +01:00