feat(governance): verify private mirror provenance - #17
Open
monkseekee-max wants to merge 1 commit into
Open
Conversation
Bind mirror source and target trees to a protected-main Ed25519 receipt. Keep every HMG source-read credential out of the target repository.
Contributor
Author
|
@xionghaoh Independent Core Maintainer review is the remaining merge condition. All central checks are green. HMG source authority PR #55 has merged at |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Outcome
Adds a read-only required gate for HMG-DEV-brach exact-source mirror pull requests. The gate verifies an Ed25519 receipt issued from protected HMG main and requires the signed source tree, signed export tree, and actual pull-request tree to be identical.
No HMG source-read or target-write credential is exposed to the target repository. Merge-group events fail closed until their provenance semantics are specified.
Validation
Follow-up
After merge, HMG will pin this exact governance commit in its protected-main provenance issuer, and the HMG-DEV-brach ruleset will be updated to the same immutable required-workflow SHA.