fix(context-fabric): require source-bound release attestation - #544
fix(context-fabric): require source-bound release attestation#544seonghobae wants to merge 16 commits into
Conversation
|
Important Draft PR not reviewedDraft PRs are not automatically reviewed by default.
To automatically review draft PRs, update your CodeRabbit configuration: reviews:
auto_review:
drafts: trueThanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh protected-base repair supersedes the stale authority block above. Protected |
Scope
Strengthen Noema's Context Graph consumer ACL without copying
context-graph-contractssource or treating mutable producer PRs as authority. Noema requires exact release-source manifest + independently retained attestation digests, protected source ref and signer workflow, canonical Context Assertion/CloudEvent profile identities, and versionedcontext-assertion-envelope-preserving-admission-v1capability evidence. Cross-service SQL, mutable producer source, provider routing and foreign security authority remain out of scope.Retained TDD lineage
RED
1e2603bb...→ production20b8bead...bound exact protected-source manifest/attestation evidence; RED834b4ac8...→4f04a78a...added finite canonical capability metadata; REDe0f0dc0b...→c72ce1cb...added versioned envelope-preserving admission. Hosted fitness failures were repaired without weakening immutable-release semantics. The latest predecessor showed a Markdown-sensitive raw-substring fixture;d5ecf8331d78db1e5d1b5505e818a1f8aed01076strips backticks only for the semantic assertion while preserving the exactimmutable released context-graph-contractsrequirement.Current exact authority — 2026-09-06 KST
main@e1ac9d50f6c646f04be8c137c8acdc7200182fcd;d5ecf8331d78db1e5d1b5505e818a1f8aed01076;ci 33952078330, requiredSecurity Scan 33952078410,reviewer-ci 33952078464, andpatch-validator-image 33952078542are terminal success;95144d5bcf8f1cb4b9a7c552ede66737c23d6bca. The reviewer success above predates that repaired semantic-evidence contract reaching protected truth, so it is workflow-surface evidence rather than merge-authoritative semantic GREEN.Keep the source unchanged and Draft. After #546 reaches protected truth, regenerate semantic reviewer evidence for this exact head and re-read current governance. Do not promote mutable producer evidence, weaken the release attestation contract, source-churn for runners, self-approve, rewrite history, or absorb Context Graph/CO/security owner authority.