Skip to content

fix(ci): harden SLSA pin guardrail + drop stale ci-local date - #754

Merged
millsmillsymills merged 2 commits into
mainfrom
fix/slsa-guardrail-661
Jun 23, 2026
Merged

fix(ci): harden SLSA pin guardrail + drop stale ci-local date#754
millsmillsymills merged 2 commits into
mainfrom
fix/slsa-guardrail-661

Conversation

@millsmillsymills

Copy link
Copy Markdown
Owner

Hardens the #661 watch guardrail and clears a stale date the #751 sweep missed.

Changes

Verification

  • shellcheck + shfmt -d clean on assert-slsa-pin-fresh.sh.
  • Default run (offline): unchanged WARN output, now citing #661.
  • Opt-in run: OK: upstream latest (v2.1.0) matches the pinned version — nothing newer to evaluate.

No behavior change to the pin itself — the bump remains upstream-gated on slsa-framework/slsa-github-generator#4490.

Refs #661

🤖 Generated with Claude Code

millsmillsymills and others added 2 commits June 23, 2026 15:42
ci-local.sh restated a "2026-06-02 deadline" string that drifted from the
script's own DEADLINE constant (2026-09-16); PR #751 fixed the date in
deploy.yml and the script but missed this echo. Make the echo defer to the
script so the date lives in one place.

Add an opt-in upstream check (MMS_CHECK_SLSA_UPSTREAM=true) that queries the
releases API and flags when upstream cuts a release newer than the pinned
one — the human-action trigger #661 waits on. Off by default so the lint
stays offline and deterministic, matching the MMS_VERIFY_STATE_BUCKET opt-in
pattern. Point LOCAL_ISSUE at #661 (supersedes #389).

Refs #661

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@millsmillsymills
millsmillsymills enabled auto-merge (squash) June 23, 2026 23:01
@millsmillsymills
millsmillsymills merged commit 002c721 into main Jun 23, 2026
5 checks passed
@millsmillsymills
millsmillsymills deleted the fix/slsa-guardrail-661 branch July 8, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant