Skip to content

fix(release): restack SBOM JSON integrity on d99ff3 main - #322

Merged
seonghobae merged 2 commits into
mainfrom
fix/release-sbom-json-integrity-d99ff3
Aug 14, 2026
Merged

fix(release): restack SBOM JSON integrity on d99ff3 main#322
seonghobae merged 2 commits into
mainfrom
fix/release-sbom-json-integrity-d99ff3

Conversation

@seonghobae

Copy link
Copy Markdown
Contributor

Purpose

Rebuild only PR #320's bounded release-evidence SBOM JSON-integrity hardening onto current protected main after #316 advanced the base. No predecessor CI, review, scanner, coverage, release, deployment, production, legal-rights, or acquisition authority transfers.

Exact construction

  • protected main immediately before publication: d99ff3912bd80c5abc4d1aca6c26dd3901ae6f58;
  • source PR fix(release): restack ambiguous SBOM JSON integrity on current main #320 exact unchanged head at the pre-write refetch: 994786634a18c9840e10fb38fb242b324f532abd;
  • successor exact head: 3746f384857a984635a869a9f0443c4f802ccfa3;
  • ancestry: 2 commits ahead / 0 behind protected main, merge base exactly protected main;
  • net scope: exactly two paths: scripts/release-evidence.mjs and test/release-sbom-json-integrity.test.ts.

Protected-main movement since #320's base changes only workflow-registry audit source/tests, so this successor preserves the exact #320 release-evidence behavior without overwriting intervening protected bytes.

Release-evidence integrity contract

The SBOM boundary fatal-decodes UTF-8 and rejects escape-equivalent duplicate decoded JSON object names before JSON.parse, CycloneDX validation, or immutable release-evidence binding. Existing bounded source/SBOM reads, exact release repository/ref/version/SHA identity, digests, manifest identity, and checksum semantics remain unchanged. This does not prove a release exists, provenance was accepted, deployment occurred, or outbound rights were authorized.

Evidence boundary

Keep Draft until this unchanged exact head receives fresh terminal-success application ci, reviewer-ci, protected-base-eligible central Security Scan, exact 100% configured owned production statement/branch/function/line coverage with realistic tests, and zero valid unresolved findings. Pending, queued, skipped, absent, neutral, failed, cancelled, stale, predecessor, status-only, model-only, or rate-limited evidence is non-passing.

Immediately before Ready or merge, independently re-resolve protected main, exact head/base/ancestry, reviews/threads, checks and checkout SHAs, live rulesets, central Security Scan revision/triggers/base filters/thresholds, releases, and writer state.

Supersedes #320 only after fresh exact-head verification and protected integration.

@coderabbitai

coderabbitai Bot commented Aug 14, 2026

Copy link
Copy Markdown

Important

Review skipped

Draft detected.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 0e3d169e-5812-4a4b-babd-c4b74c6ddf80

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@seonghobae
seonghobae marked this pull request as ready for review August 14, 2026 18:37
@seonghobae
seonghobae merged commit 4b45caa into main Aug 14, 2026
16 checks passed
@seonghobae
seonghobae deleted the fix/release-sbom-json-integrity-d99ff3 branch August 14, 2026 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant