Skip to content

Sprint 15.1 — Vendor and pin secure-metadata v0.1.0 #15

Description

@maruson08

Problem / motivation

Secure Tools needs the immutable secure-metadata v0.1.0 browser release without weakening its same-origin dependency boundary.

Scope

Download the v0.1.0 GitHub Release browser artifact to a temporary directory, verify SHA-256 locally and against SHA256SUMS, then vendor the unchanged artifact with tag-sourced LICENSE/package metadata and an adjacent provenance README. Extend the release gate.

Non-goals

No rebuild, npm/CDN/runtime fetch, source map, tarball, source tree, automatic update, or Secure_Metadata change.

Acceptance criteria

  • The vendored browser artifact SHA-256 is exactly 8d0b8a1addf904760aa1f52378fb05eed6540520cb05fe2320d77011cba69c28.
  • Approved vendor files, name, version 0.1.0, MIT license, tag, commit, artifact, and hash are pinned by tests.
  • Runtime import remains same-origin and the artifact bytes are unchanged.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions