Skip to content

fix(ci): bind CNPG runtime proof policy - #9

Merged
bntvllnt merged 1 commit into
mainfrom
fix/cnpg-runtime-proof-v4
Jul 19, 2026
Merged

fix(ci): bind CNPG runtime proof policy#9
bntvllnt merged 1 commit into
mainfrom
fix/cnpg-runtime-proof-v4

Conversation

@bntvllnt

Copy link
Copy Markdown
Contributor

Summary

  • require signed CNPG image-equivalence proof schema v4
  • bind exact runtime projection and 20-field neutral-default policy
  • canonicalize Docker serializer defaults identically in independent authority
  • assert exact neutral removal plus non-neutral and wrong-type retention

Verification

  • workflow YAML parsed with yq
  • embedded Bash: bash -n and ShellCheck PASS
  • full local authority run rebuilt with network disabled from exact preloaded dependency image: PASS
  • signed proof and tampered-proof negative control: PASS
  • cleanup: zero authority images, containers, or temp directories

Companion: vllnt/infra#461

The sovereign runner and organization required-workflow ruleset remain separate blockers; this workflow is still non-enforcing until those controls ship.

@bntvllnt bntvllnt self-assigned this Jul 19, 2026
@bntvllnt
bntvllnt merged commit 42f9ba2 into main Jul 19, 2026
1 check passed
@bntvllnt
bntvllnt deleted the fix/cnpg-runtime-proof-v4 branch July 19, 2026 03:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant