Skip to content

feat: add verifiable execution passports - #1

Merged
aantenore merged 5 commits into
mainfrom
feat/execution-passport
Jul 17, 2026
Merged

feat: add verifiable execution passports#1
aantenore merged 5 commits into
mainfrom
feat/execution-passport

Conversation

@aantenore

Copy link
Copy Markdown
Owner

Outcome

Adds Execution Passport v1: a strict in-toto Statement that binds a RunBundle, its complete ConformanceReport, and an opaque externally validated OASF record without embedding those artifacts.

Trust and interoperability

  • exactly three ordered, content-free subjects
  • project-owned versioned predicate URI
  • explicit run and conformance states
  • fail-closed report, receipt, identity, rule, and time consistency
  • optional placement evidence as metadata-only digest descriptors
  • external DSSE/Sigstore boundary with explicit unsigned vs authenticated consumer policy
  • mapping-only OASF and StageFabric adapters with documented information loss

Verification

  • npm run release:check
  • 81 tests
  • lint, typecheck, coverage, build, publint, API type and package smoke checks
  • production dependency audit: 0 vulnerabilities
  • repository identity and forbidden-string audit passed

No provider SDK or signing implementation is coupled to the core.

@aantenore
aantenore merged commit fd99b6e into main Jul 17, 2026
9 checks passed
@aantenore
aantenore deleted the feat/execution-passport branch July 17, 2026 22:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant