Skip to content

VSTD 1.2.0: bind SBOM evidence and prepare immutable GitHub releases #25

Description

@TimeLordRaps

Coordinate

VSTD 1.2.0 release-candidate supply-chain implementation and repository-setting evaluation. Existing exact-byte manifests, reproducible
builds, signatures, and GitHub artifact attestations remain authoritative for their named
properties.

Target

  • Verify the current official GitHub mechanism and constraints for immutable releases
    before changing repository settings.
  • Evaluate a Software Package Data Exchange (SPDX) or CycloneDX software bill of materials
    (SBOM) generated from the exact release commit and distributions.
  • Determine how the SBOM digest should be bound beside existing release artifacts without
    making it self-referential.
  • Specify additive correction behavior when released metadata is wrong.

Exit criteria

  • Any mechanism is documented from current official behavior, not assumed.
  • SBOM bytes and provenance are bound to the exact release coordinate.
  • Existing manifests and attestations are complemented, never replaced or overstated.
  • Immutability does not conceal the need for additive corrections or revocation evidence.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestrelease-integrityRelease provenance, byte identity, or artifact bindingsecurity-boundaryExecution, trust, or observation boundary

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions