Skip to content

M11.2: enforce strict release integrity - #2

Merged
pgousdal merged 3 commits into
mainfrom
work/m11.2-strict-release-integrity
Sep 5, 2026
Merged

pgousdal merged 3 commits into
mainfrom
work/m11.2-strict-release-integrity

Conversation

@pgousdal

@pgousdal pgousdal commented Sep 5, 2026

Copy link
Copy Markdown
Contributor

Adds a strict release-ref verifier and wires it into both CI policy tests and the release workflow. Releases now require a valid SemVer-style vX.Y.Z tag bound to the exact checked-out GitHub commit, with explicit OCI source/version/revision labels. Existing immutable Action pins, multiarch publishing, SBOM, provenance and attestation remain unchanged.

@pgousdal
pgousdal merged commit 7a64df3 into main Sep 5, 2026
1 check passed
@pgousdal
pgousdal deleted the work/m11.2-strict-release-integrity branch September 6, 2026 02:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant