Skip to content

Pin Sigstore-enforcing OpenSecret SDK#48

Draft
AnthonyRonning wants to merge 3 commits into
masterfrom
codex-sigstore-tee-attestation-maple-proxy
Draft

Pin Sigstore-enforcing OpenSecret SDK#48
AnthonyRonning wants to merge 3 commits into
masterfrom
codex-sigstore-tee-attestation-maple-proxy

Conversation

@AnthonyRonning

@AnthonyRonning AnthonyRonning commented Jul 23, 2026

Copy link
Copy Markdown
Contributor

Summary

  • pin opensecret to the exact reviewed OpenSecret-SDK commit from Verify enclave releases from Sigstore snapshots OpenSecret-SDK#89
  • disable SDK default features for normal and release builds
  • expose the insecure local mock-attestation path only through an explicit proxy feature used by just run-local
  • document the new update-time Sigstore/Rekor trust boundary and rollout constraints

Dependency and rollout status

This PR is intentionally a draft and must not merge or publish yet. It depends on OpenSecretCloud/OpenSecret-SDK#89, whose embedded release-policy snapshot is deliberately empty until the first signed backend release is published from OpenSecretCloud/opensecret#240. Before promotion, repin this dependency to the released SDK commit/version containing that populated snapshot.

The exact SDK source in this branch is commit 1bd7196043b26b3a2f8080534bd14031afcd5cc8. Runtime verification is fail-closed and performs no GitHub or Sigstore network lookup.

Validation

  • default-feature test suite: 22 passed
  • all-feature test suite: 22 passed
  • cargo check, cargo clippy, formatting, and release build passed
  • default dependency feature tree confirms mock attestation is disabled
  • lockfile resolves the exact SDK commit
  • independently reviewed from security and integration/rollout angles; no major findings remain

No live publication or unreleased-artifact smoke test was attempted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant