Skip to content

Require certification and publication tooling to descend from the deny-list merge #861

Description

@MaxGhenis

PR #857 adds a sealed deny-list for the candidate-26 pool enforced in loaders, receipts, selection manifests, and the publisher's release contract. Merged code cannot constrain a stale checkout: a builder or publisher run from a tree predating the merge still admits the pool through the gate-failed opt-in. Follow-up: make certification and publication refuse to run from a tree that does not descend from the deny-list merge commit (record the merge SHA once #857 lands), and log the check in the release receipt. Refs #856, #857.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions