Skip to content

feat(release): signed, SHA-pinned musl release with build provenance - #126

Merged
hyperpolymath merged 1 commit into
mainfrom
feat/signed-pinned-release
Oct 9, 2026
Merged

hyperpolymath merged 1 commit into
mainfrom
feat/signed-pinned-release

Conversation

@hyperpolymath

@hyperpolymath hyperpolymath commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Summary

PR 1 of 2 for a signed, pinned release pipeline. When a v* tag is pushed, release.yml will build a static squabble binary for x86_64-unknown-linux-musl using the workspace MSRV toolchain (1.85.0). It publishes the binary with a SHA256SUMS file and a Sigstore build-provenance attestation for both files. The Justfile's release-tag now creates a signed tag. The crate version on main is 0.1.0.

Sequencing. No tag is created or pushed by this PR.

  1. This PR merges.
  2. The owner pushes a signed tag v0.1.0; tagging is the owner's call, and tags here are immutable.
  3. release.yml runs and publishes squabble-x86_64-linux-musl and SHA256SUMS, with an attestation.
  4. PR 2 adds the consumer action (verify-satisfied). It pins the real sha256 from that release and checks it with gh attestation verify.

Changes

  • .github/workflows/release.yml is rewritten in block YAML (not KYAML). The SPDX header is kept.
    • Trigger and permissions: push: tags: ['v*']. Top-level permissions are contents: read only.
    • build job:
      • checkout with persist-credentials: false
      • dtolnay/rust-toolchain with toolchain: 1.85.0 and targets: x86_64-unknown-linux-musl
      • sudo apt-get install -y musl-tools
      • cargo build --locked --release -p squabble-cli --target x86_64-unknown-linux-musl
      • stages dist/squabble-x86_64-linux-musl and dist/SHA256SUMS, running sha256sum inside dist/ so the names are bare
      • a step that fails if either file is missing or empty, then runs sha256sum -c
      • upload-artifact with if-no-files-found: error
    • release job:
      • needs: build. Its permissions are exactly contents: write, id-token: write and attestations: write.
      • download-artifact, then a guard that fails on an empty or incomplete dist/
      • attest-build-provenance with subject-path: 'dist/*', with no skip condition
      • softprops/action-gh-release with files: dist/*, generate_release_notes: true and fail_on_unmatched_files: true
    • Removed: the git-cliff changelog job, and the language auto-detect build stub.
    • Pinning: every uses: is pinned to a full commit SHA, with its tag in a trailing comment.
  • .github/workflows/actions.lock is edited by hand. Only the release.yml entry and the records it alone used are touched. gh actions-lock was not run in rewrite/fix mode.
    • The release.yml list now names the six SHA refs.
    • It adds three SHA-keyed dependencies: records:
      • actions/download-artifact@3e5f45b2…
      • actions/attest-build-provenance@4d101475…, with its nested actions/attest@508db95…, which was already recorded
      • softprops/action-gh-release@efb35369…
    • It prunes the two tag-keyed records that only release.yml used: actions/attest-build-provenance@v4.2.2 and softprops/action-gh-release@v3.0.3.
    • The lock stays transitively closed. Repo and owner IDs were re-read through GraphQL.
  • Justfile release-tag: git tag -a becomes git tag -s. The Immutable-Tags ruleset has a required_signatures rule. The recipe now produces a signed tag whatever the local tag.gpgsign setting is; on this machine tag.gpgsign=true was already set, so the behaviour here does not change.

Type of change

  • New feature (CI/release pipeline). No Rust source, public API or behaviour of squabble changes.

📌 New pins

Head SHA: 9853570e107db3f4c5aec5b3266ed2c9e9703902

Action Pinned commit Tag
actions/checkout 3d3c42e5aac5ba805825da76410c181273ba90b1 v7.0.1
dtolnay/rust-toolchain 6c977a6ca4077a0ceb28ffbe03f59d46e9ac8772 no tag (see below)
actions/upload-artifact 043fb46d1a93c77aae656e7c1c64a875d1fc6a0a v7.0.1
actions/download-artifact 3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c v8.0.1
actions/attest-build-provenance 4d101475d8b20a2381f78447822ac1eab6504dd8 v4.2.2
↳ nested actions/attest 508db95dd578ae2727ebd6217d5ba78e4fbda05d v4.2.1
softprops/action-gh-release efb35369e0ad2afab669f228072c1b0d510eae64 v3.0.3 (peeled commit; the annotated tag object is e598afbe…)

Each SHA was checked with git ls-remote against the upstream tag.

dtolnay/rust-toolchain@6c977a6c is an untagged master commit from 2026-08-04, the merge of #182, and an ancestor of the moving v1 branch. It is the SHA this repo's lock already records for the standards reusable workflows. It predates upstream's input-hardening change (83d0610, "Safely handle action inputs"). The inputs here are constant strings, so that change does not apply to this workflow.

No other lockfile records, container digests or Cargo.lock entries change.

RSR Quality Checklist

Required

  • Tests pass: cargo +1.85.0 test --locked --workspace gives 279 passed, 0 failed (123 + 64 + 59 + 33).
  • Code is formatted: N/A. No Rust source is changed; the only changes are YAML, the lockfile and one Justfile line.
  • Linter is clean: not fully.
    • actionlint is clean on release.yml.
    • Pre-commit editorconfig-checker fails on Justfile lines 210–216 (indentation). That failure is already on origin/main: the same check on git show origin/main:Justfile fails identically. This PR changes only line 533.
    • The repo-wide lint-workflows (Workflow Security Linter) red is pre-existing; see "CI on this head" under Testing.
  • No banned language patterns. YAML, lockfile and Justfile only.
  • No unsafe blocks without // SAFETY:: N/A, no Rust changed.
  • No banned functions: N/A, no Rust, Idris, Lean or OCaml changed.
  • SPDX header present on the modified release.yml (line 1, kept). actions.lock keeps the machine-generated header it already had, and Justfile keeps its existing header.
  • No secrets, credentials or .env files. Pre-commit gitleaks and detect-private-key passed.

As Applicable

  • STATE.a2ml: N/A. A2ML is retired estate-wide and is not created or edited here.
  • ECOSYSTEM.a2ml: N/A, same reason.
  • META.a2ml: N/A, same reason.
  • Documentation: N/A in this PR. The verify commands are in the release.yml header comment; user-facing install docs land with PR 2.
  • TOPOLOGY.md: N/A, no architecture change.
  • CHANGELOG: not updated. The release now uses generate_release_notes: true, and the git-cliff job is gone.
  • New dependencies license review: N/A. No crate dependencies are added; only CI actions are pinned.
  • ABI/FFI: N/A, untouched.

Testing

How has this been verified?

Command Result
rustup toolchain install 1.85.0 --profile minimal --target x86_64-unknown-linux-musl (into the estate tools rustup) installed rustc 1.85.0 (4d91de4e4 2025-02-17)
cargo +1.85.0 build --locked --release -p squabble-cli --target x86_64-unknown-linux-musl rc=0; produced ELF 64-bit LSB pie executable, x86-64, static-pie linked, 2,343,240 bytes. squabble --version printed squabble 0.1.0
cargo tree --locked -p squabble-cli --target x86_64-unknown-linux-musl -e normal,build 29 lines. No C-compiling crate (ring, cc, *-sys) is in the default tree, which is why the musl link works here without musl-gcc
cargo metadata --locked (rust-version of every package) the highest in the default graph is 1.85; wasip2 declares 1.87.0 but is not in the musl default tree, and the 1.85.0 build above succeeded
cargo +1.85.0 test --locked --workspace 279 passed, 0 failed
bash scripts/check-lock-sync.sh rc=0: in sync, transitively closed, 0 dangling edges, every workflow keyed
gh actions-lock --no-fix rc=0; the working tree was byte-identical before and after
actionlint .github/workflows/release.yml (1.7.7) rc=0
pre-commit run --files <the 3 files> all hooks pass except two (details below)
bash standards/.githooks/docstring-scan.sh --worktree --check rc=0. No shell functions were added or modified (0 touched), so §5d does not apply
git log -1 --show-signature Good "git" signature … ED25519

Positive controls. Each one shows that a check above can return a failure.

  • Dropping the softprops@efb35369 record makes check-lock-sync.sh exit 1.
  • A wrong commit: digest on the download-artifact SHA record makes gh actions-lock --no-fix exit 2.
  • A planted needs: buidl makes actionlint exit 1.
  • gh actions-lock --no-fix exited 0 on the dangling-edge plant. That is the blind spot documented in check-lock-sync.sh; check-lock-sync.sh is the gate that catches it.

The two pre-commit hooks that did not pass:

  • editorconfig-checker fails on Justfile lines 210–216. This is pre-existing on origin/main (see the checklist above), and this PR changes only line 533.
  • validate-k9 could not run. Its hook repo, https://github.com/hyperpolymath/k9-pre-commit, does not resolve: git fetch reports "Repository not found", and GraphQL repository(...) returns NOT_FOUND. As a result, pre-commit run aborts before any hook runs. Every other hook was run from a scratch copy of .pre-commit-config.yaml with only that repo block removed. No .k9 files are changed in this PR.

Not verified locally, and only provable by the first tag run:

  • apt-get install musl-tools on the runner. It is not needed for the current default dependency tree, but is kept for any future C dependency.
  • actions/download-artifact reading a same-run artifact without actions: read. The README at 3e5f45b2 scopes default access to the current run.
  • The OIDC and Sigstore attestation itself. The repo is public, so it uses the Sigstore public-good instance and the attestation is publicly verifiable.
  • softprops/action-gh-release creating the release.

CI on this head (9853570e)

Read from commits/9853570e…/check-runs with --paginate (52 runs), commits/9853570e…/statuses (plural, deduped by context), REST pulls/126/reviews, GraphQL reviewThreads and rules/branches/main.

  • Effective rules on main: deletion, non_fast_forward, required_status_checks. The only required context is scan / gitleaks, and it is success.
  • Check-runs: 47 success, 3 skipped (automerge, rust-ci / Cargo audit (security), rust-ci / llvm-cov line coverage; skipped satisfies, but they carry no evidence), 2 failure (both lint-workflows, one run per trigger).
  • Apps that reported: github-actions, codefactor-io, gitguardian, github-advanced-security, semgrep-code-hyperpolymath and sonarqubecloud (Quality Gate passed) as check-runs, plus CodeRabbit and Codeac analyze results as legacy statuses. Codeac says "1 errors and 3 warnings" in a success state, which is the same text it gives on main @ a4cd088.
  • CodeRabbit: APPROVED, "No actionable comments were generated". There are 0 review threads and 0 inline comments.
  • Code scanning: I took the set difference by alert number. The 31 open alerts on refs/pull/126/merge (Hypatia and CodeQL analyses of merge commit 76836fa6) are a subset of the 46 open alerts on main, so this PR introduces 0 alerts. That includes the pre-existing Hypatia 🔧 CodeRabbit CI Fix: Fix failing Dogfood Gate K9 contracts and Groove manifest checks #64 and Feat/green polarity classifier #76, which fire on the case-folded duplicate Swatinem/rust-cache / swatinem/rust-cache@6323deb1 record already present in main's actions.lock. This PR does not touch that record.
  • lint-workflows is red, and it is pre-existing.
    • The failing step is Check SHA-Pinned Actions; Check SPDX Headers and Check Permissions Declaration pass.
    • The same step is red on main (run 36649482714 at b12657f5, whose .github/workflows/ is identical to a4cd088; 39 findings). This head has 36 findings, all in files this PR does not change. The PR removes 3 of them, the tag-pinned release.yml refs.
    • 5 of the 36 are the linter matching the nested uses: keys inside actions.lock itself. That is a linter false positive, and main has the same 5.
    • Deferral: lint-workflows is deferred to lint-workflows: Check SHA-Pinned Actions red on main (31 tag-pinned refs + 5 actions.lock false positives) #127 (acceptance: the step is green on main, the 31 refs are SHA-pinned and lock-covered, and the linter no longer reads actions.lock).

Screenshots

N/A. Terminal results are in the Testing table above.

🤖 Generated with Claude Code

https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML

Rewrite release.yml so a v* tag produces a real, verifiable artefact:

- build: checkout, dtolnay/rust-toolchain at 1.85.0 (the workspace MSRV)
  with the x86_64-unknown-linux-musl target, musl-tools, then
  `cargo build --locked --release -p squabble-cli --target
  x86_64-unknown-linux-musl`. Stage dist/squabble-x86_64-linux-musl and
  dist/SHA256SUMS (bare names), fail if either is missing or empty, and
  upload dist/ as one artifact.
- release: needs build; job permissions are exactly contents: write,
  id-token: write, attestations: write. Download dist/, refuse an empty
  or incomplete dist/, attest build provenance for dist/* with no skip
  condition, then publish dist/* with generated release notes.
- Drop the git-cliff changelog job and the language auto-detect stub.
- Top-level permissions are contents: read only.

Every uses: is pinned by full commit SHA with the tag in a comment.
actions.lock is edited by hand for the release.yml entry only: its list
now names the six SHA refs, three SHA-keyed dependency records are added
(download-artifact, attest-build-provenance with its nested actions/attest,
softprops/action-gh-release), and the two tag-keyed records that only
release.yml used (attest-build-provenance@v4.2.2,
softprops/action-gh-release@v3.0.3) are pruned. The lock stays
transitively closed.

Justfile release-tag now creates a signed tag (git tag -s) so the
Immutable-Tags required_signatures rule does not depend on local
tag.gpgsign config.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_015bTuGfwCcvjrmNFejydTML
@coderabbitai

coderabbitai Bot commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Review in Change Stack →

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: ASSERTIVE
  • Plan: Advanced
  • Run ID: f6f661f1-b015-44f3-a7c7-6874c46d8eba

📥 Commits

Reviewing files that changed from the base of the PR and between a4cd088 and 9853570.


⛔ Files ignored due to path filters (1)
  • .github/workflows/actions.lock is excluded by !**/*.lock

📒 Files selected for processing (2)
  • .github/workflows/release.yml
  • Justfile

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📜 Recent review details
⏰ Context from checks skipped due to timeout. (10)
  • GitHub Check: governance / Validate Hypatia Baseline
  • GitHub Check: Dogfooding compliance summary
  • GitHub Check: rust-ci / Cargo check + clippy + fmt
  • GitHub Check: governance / Workflow security linter
  • GitHub Check: governance / Actions lockfile verify
  • GitHub Check: governance / Code quality + docs
  • GitHub Check: hypatia / Hypatia Neurosymbolic Analysis
  • GitHub Check: analyze (actions, none)
  • GitHub Check: Hypatia neurosymbolic scan
  • GitHub Check: semgrep-cloud-platform/scan

⚠️ CI failures not shown inline (2)

GitHub Actions: Workflow Security Linter / 0_lint-workflows.txt: feat(release): signed, SHA-pinned musl release with build provenance

Conclusion: failure

View job details

##[group]Run echo "=== Checking Action Pinning ==="
 �[36;1mecho "=== Checking Action Pinning ==="�[0m
 �[36;1m# Find any uses: lines that don't have @SHA format�[0m
 �[36;1m# Pattern: uses: owner/repo@<40-char-hex>�[0m
 �[36;1munpinned=$(grep -rnE "^[[:space:]]+uses:" .github/workflows/ | \�[0m
 �[36;1m  grep -v "@[a-f0-9]\{40\}" | \�[0m
 �[36;1m  grep -v "uses: \./\|uses: docker://\|uses: actions/github-script" || true)�[0m
 �[36;1m�[0m
 �[36;1mif [ -n "$unpinned" ]; then�[0m
 �[36;1m  echo "ERROR: Found unpinned actions:"�[0m
 �[36;1m  echo "$unpinned"�[0m
 �[36;1m  echo ""�[0m
 �[36;1m  echo "Replace version tags with SHA pins, e.g.:"�[0m
 �[36;1m  echo "  uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.1"�[0m
 �[36;1m  exit 1�[0m
 �[36;1mfi�[0m
 �[36;1mecho "All actions are SHA-pinned"�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 === Checking Action Pinning ===
 ERROR: Found unpinned actions:
 .github/workflows/push-email-notify.yml:43:        uses: hyperpolymath/smtp-notify-action@v0.3.0
 .github/workflows/pages.yml:24:        uses: actions/checkout@v7.0.1
 .github/workflows/pages.yml:26:        uses: actions/checkout@v7.0.1
 .github/workflows/pages.yml:43:        uses: actions/upload-pages-artifact@v5.0.0
 .github/workflows/pages.yml:56:        uses: actions/deploy-pages@v5.0.1
 .github/workflows/dogfood-gate.yml:34:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:75:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:121:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:217:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:276:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:328:        uses: actions/checkout@v7.0.1
 .github/workflows/quality.yml:38:        uses: editorconfig-checker/action-editorconfig-checker@v3.0.0
 .github/workflows/codeql.yml:38:        uses: actions/checkout@v7.0.1
 .github/workflows/codeq...

GitHub Actions: Workflow Security Linter / lint-workflows: feat(release): signed, SHA-pinned musl release with build provenance

Conclusion: failure

View job details

##[group]Run echo "=== Checking Action Pinning ==="
 �[36;1mecho "=== Checking Action Pinning ==="�[0m
 �[36;1m# Find any uses: lines that don't have @SHA format�[0m
 �[36;1m# Pattern: uses: owner/repo@<40-char-hex>�[0m
 �[36;1munpinned=$(grep -rnE "^[[:space:]]+uses:" .github/workflows/ | \�[0m
 �[36;1m  grep -v "@[a-f0-9]\{40\}" | \�[0m
 �[36;1m  grep -v "uses: \./\|uses: docker://\|uses: actions/github-script" || true)�[0m
 �[36;1m�[0m
 �[36;1mif [ -n "$unpinned" ]; then�[0m
 �[36;1m  echo "ERROR: Found unpinned actions:"�[0m
 �[36;1m  echo "$unpinned"�[0m
 �[36;1m  echo ""�[0m
 �[36;1m  echo "Replace version tags with SHA pins, e.g.:"�[0m
 �[36;1m  echo "  uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v6.0.1"�[0m
 �[36;1m  exit 1�[0m
 �[36;1mfi�[0m
 �[36;1mecho "All actions are SHA-pinned"�[0m
 shell: /usr/bin/bash -e {0}
 ##[endgroup]
 === Checking Action Pinning ===
 ERROR: Found unpinned actions:
 .github/workflows/push-email-notify.yml:43:        uses: hyperpolymath/smtp-notify-action@v0.3.0
 .github/workflows/pages.yml:24:        uses: actions/checkout@v7.0.1
 .github/workflows/pages.yml:26:        uses: actions/checkout@v7.0.1
 .github/workflows/pages.yml:43:        uses: actions/upload-pages-artifact@v5.0.0
 .github/workflows/pages.yml:56:        uses: actions/deploy-pages@v5.0.1
 .github/workflows/dogfood-gate.yml:34:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:75:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:121:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:217:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:276:        uses: actions/checkout@v7.0.1
 .github/workflows/dogfood-gate.yml:328:        uses: actions/checkout@v7.0.1
 .github/workflows/quality.yml:38:        uses: editorconfig-checker/action-editorconfig-checker@v3.0.0
 .github/workflows/codeql.yml:38:        uses: actions/checkout@v7.0.1
 .github/workflows/codeq...

🧰 Additional context used
📚 Code guidelines (1)
.github/copilot-instructions.md — auto-discovered

📓 Path-based instructions (1)
Source excerpt: SPDX: `MPL-2.0` on all new files.

📄 CodeRabbit inference engine (.github/copilot-instructions.md)

Files:

  • Justfile



🔇 Additional comments (1)
.github/workflows/release.yml (1)

99-99: 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier

Enforce signed tags before publishing releases.

The release workflow does not verify the signature of the pushed v* tag before publication. A signed-tag recipe does not prevent direct unsigned tag pushes. Enforce signed v* tags in repository rules or verify the tag against an approved signer before attestation and publication.





📝 Summary

Summary by CodeRabbit

  • Release Process
    • Releases now publish a verified Linux binary with checksum and provenance information.
    • Tags containing -rc, -beta or -alpha are marked as prereleases.
    • Release tags are now signed.

Walkthrough

The release workflow now builds and verifies one Linux musl binary before publishing it with provenance attestation. The release-tag command now creates a signed Git tag.

Changes

Signed Binary Release

Layer / File(s) Summary
Create signed release tag
Justfile
release-tag now creates a signed Git tag.
Build and verify release asset
.github/workflows/release.yml
The workflow uses Rust 1.85.0 to build the x86_64-unknown-linux-musl binary. It stages the binary and SHA256SUMS, verifies them, and uploads the artifact.
Validate and publish release
.github/workflows/release.yml
The release job downloads and validates the build artifact, attests provenance, and uploads the files to the GitHub Release. The changelog job was removed. Release notes are generated, and tags containing -rc, -beta or -alpha remain prereleases.

Priority: ⬇️ Low

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Feature


Merge Risk

Merge Risk: ⚪ Minimal · up to 98535

The release pipeline is ready for normal checks before merge; no concrete release-blocking issue was found.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 98535

The pipeline strengthens artifact checks and separates build permissions from publication authority. Remaining uncertainty concerns enforcement of trusted, immutable release tags and recovery after interrupted publication. No security bypass has been demonstrated.

Retained concerns

  • Low · security · inferred: Newly published, attested executable assets depend on repository-side release-tag authorization whose enforcement is unavailable. The workflow's lack of signature validation predates this PR, but the previously dormant binary-publication and attestation outputs are now active. This is an unresolved trust dependency, not a verified unsigned-tag bypass.

Security review details

Security Blast Radius

  • inferred — The visible authority covers repository release publication and provenance issuance. A compromised accepted release source could affect consumers executing the resulting CLI. No downstream deployment, tenant access, additional credentials, or consumer rollout is established by this PR's evidence.

Security Findings and Attack Paths

  • inferred — No retained security finding is supplied. The deferred candidate concerns an actor able to push a matching tag having unauthorized source built, attested, and published if remote release authorization is insufficient. Whether such a tag is accepted, and whether the actor would be unauthorized under repository policy, remain unresolved; unsigned-tag reachability is not verified.

Trust Boundaries and Controls

  • inferred — Checksum checks protect the declared artifact-transfer consistency boundary, and job permissions separate build execution from publication authority. Because the binary and manifest are produced together, matching checksums do not independently authorize the source. Provenance publication likewise does not substitute for trusted release-tag admission.

Resilience and Maintainability Implications

  • inferred — Declared missing-file, checksum, and attestation failures stop progression before the release action. This supports fail-closed normal ordering, but does not prove transactional publication or safe reconciliation of old assets and attestations after interrupted uploads or reruns. No inconsistent published state was demonstrated.

Hardening Proposals

  • proposed — Establish and document the effective approved-publisher and immutable-tag policy before relying on release provenance as an authorization signal. If repository rules do not enforce the intended signed-tag policy, add an appropriate admission control. Separately validate interrupted-publication and rerun recovery against the pinned actions.



🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 0…
Linked Issues check Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check Passed Check skipped because no linked issues were found for this pull request.
Title check Passed The title clearly and concisely describes the signed, SHA-pinned musl release and build provenance changes.
Description check Passed The description includes all required template sections, detailed changes, testing evidence, checklist results, known limitations, and screenshots status.


✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR


  • Autofix · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

I signed the tag with careful paws,
Then built one binary, checked its laws.
A checksum guards the files in line,
Provenance joins the release design.
This rabbit hops as tags take flight!

Comment @coderabbitai help to get the list of available commands.

@sonarqubecloud

sonarqubecloud Bot commented Oct 9, 2026

Copy link
Copy Markdown

@hyperpolymath
hyperpolymath merged commit b854d17 into main Oct 9, 2026
52 of 54 checks passed
@hyperpolymath
hyperpolymath deleted the feat/signed-pinned-release branch October 9, 2026 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant