Attest distributed PDF artifacts and visual fidelity #9
Loading…
Reference in a new issue
No description provided.
Delete branch "audit/pdf-artifact-provenance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Scope and dependency
Stacked on approved reviewed-media work in #3 so the PDF attestation can bind the deterministic local inputs without duplicating generator changes. The base is
audit/deterministic-media-inputsto keep this review limited to provenance, CI, docs, tests, and refreshed draft artifacts; retarget tomainafter #3 merges. Do not merge from this task.Summary
pdftoppm24.02.0 and fail closed if either the CI Ubuntu release, exact Poppler package, runtime version, or provenance toolchain declaration driftsVerification
make clean && make attest-pdfs— passed with fresh LuaLaTeX PDFs and pinned Poppler 24.02.0 rasterizationmake test— 26 tests passedreviewed PDF inputs differsha256 does not match its committed provenancebuild rendered pages differgit diff --check— passed10780ccadbdb3bThe workflow only gates CI; it does not upload, publish, deploy, or regenerate network media.
WIP: Attest distributed PDF artifactsto Attest distributed PDF artifacts and visual fidelityclawlter referenced this pull request2026-07-12 23:24:45 -04:00
Closing without merge because the owner cancelled the
code-security-audit-2026-07campaign. This does not revert previously merged work.Pull request closed