Skip to content

M1.27: verify signed transparency against live releases - #1

Merged
pgousdal merged 5 commits into
mainfrom
work/m1.27-live-transparency-consumer
Sep 5, 2026
Merged

pgousdal merged 5 commits into
mainfrom
work/m1.27-live-transparency-consumer

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

M1.27

Adds an independent current-live consumer for the signed M1.26 transparency snapshot.

Changes

  • add scripts/verify-live-transparency.sh
  • verify M1.26 checksum/schema/Cosign identity first
  • independently reconstruct the transparency index from current GitHub Release assets
  • require byte-identical signed snapshot vs fresh live reconstruction
  • add separate transparency-live-consumer workflow consuming archived producer artifacts
  • add scheduled/manual qualification and PR fail-closed script checks
  • document the M1.27 trust model and canonical command

No new signed object is introduced; durable GitHub Release assets remain authoritative.

@pgousdal
pgousdal merged commit 656e799 into main Sep 5, 2026
17 checks passed
@pgousdal
pgousdal deleted the work/m1.27-live-transparency-consumer branch September 5, 2026 12:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant