Skip to content

feat: v0.8.0 — self-update: explicit, verified, old-verifies-new - #19

Merged
avrabe merged 1 commit into
mainfrom
feat/v0.8.0-self-update
Aug 7, 2026
Merged

feat: v0.8.0 — self-update: explicit, verified, old-verifies-new#19
avrabe merged 1 commit into
mainfrom
feat/v0.8.0-self-update

Conversation

@avrabe

@avrabe avrabe commented Aug 7, 2026

Copy link
Copy Markdown
Contributor

REQ-UPDATE-001 (rivet release status v0.8.0: cuttable). varve self-update [--check] [--to] — the running binary verifies its successor against the pinned root before atomic replacement; unsigned releases, impostor signatures and unparseable versions refuse, leaving the current binary untouched (tested against a release-API double, verification-skip mutation-checked). No phone-home. Release sums now signed with the labeled provisional rolling root per the interim decision; ceremony release will be dual-signed.

🤖 Generated with Claude Code

https://claude.ai/code/session_019TNtfRjLNhEz82G2ggeeNu

REQ-UPDATE-001 verified. varve self-update checks the latest release,
verifies the successor with the running binary against the pinned
trust root, and replaces atomically; unsigned/impostor/unparseable all
refuse and leave the current binary untouched (mutation-checked). No
passive network calls. Release sums now signed with the labeled
provisional rolling root pending the ceremony (dual-signed migration
release planned).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019TNtfRjLNhEz82G2ggeeNu
@avrabe
avrabe merged commit 4e6e736 into main Aug 7, 2026
2 checks passed
@avrabe
avrabe deleted the feat/v0.8.0-self-update branch August 7, 2026 19:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant