Skip to content

[Bug] - [Mismatch between attested commit and final tagged release] #1398

@behnazh-w

Description

@behnazh-w

Description

We’ve identified an inconsistency between the commit referenced in the attestation metadata and the actual commit associated with the released version (tag) for the following packages:

  • pkg:pypi/imageio@2.37.2
  • pkg:pypi/cmdstanpy@1.3.0

Specifically, the commit recorded in the attestation does not match:

  • the final commit in the repository history for the release, nor
  • the commit pointed to by the corresponding version tag

Expected Behavior

Macaron should report the release tag commit and report mismatch in attestation.

Actual Behavior

  • Attestation commit → different
  • Release tag commit → different
  • Final repository state → aligned with tag, not attestation

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingcommit-finderThe issues related to commit finderslsa-provenanceThe issues related to SLSA provenances

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions