Skip to content

Zaibatsu v1.10.0 — Self-verifying runtime evidence packs

Choose a tag to compare

@adaliontech adaliontech released this 30 Aug 23:54
· 21 commits to main since this release
Immutable release. Only release title and notes can be modified.

Zaibatsu v1.10.0 adds a canonical runtime-evidence pack to the factory-of-software-factories control layer.

Highlights:

  • embeds the signed evidence set, verifier registry, exact JSON evidence artifacts, verifier descriptors, and immutable manifest schema in reproducible USTAR bytes
  • rechecks archive safety, canonical JSON, exact member inventory, schema and material digests, registry rules, and OpenSSH signatures
  • upgrades runtime assessments to v2 and rebuild plans to v3 so both bind and reverify the exact pack
  • rejects traversal, links, special files, duplicate/extra members, metadata and trailing-byte drift, schema/material tampering, replay, oversize input, authority inflation, and scalar type confusion
  • passes 203 tests, 90-file validation, credential-disabled candidate and tag clones, both checksum-pinned Gitleaks modes, five strict Draft 2020-12 schemas, exact artifact regeneration, and candidate/roof/tag CI

Trust boundary: the pack proves integrity and availability of the exact referenced bytes. It does not rerun verifier assertions, infer artifact semantic truth, prove key ownership or independence, grant runtime eligibility, or authorize activation, execution, deployment, secrets, or side effects.

Proof: