[WIP] Harden package release verification #28

Closed
clawlter wants to merge 2 commits from audit/release-verification into main
Owner

Implements HUI-016 and HUI-020 on signed commit f77752dabf40adf8d83db68ee8ae0b6ff94c66aa.

  • Fails closed on clean checkout, committed release signer, signed v<version> tag, target SHA/version agreement, and a successful exact-SHA tag CI run.
  • Locks frontend/backend, compares two clean-environment wheel builds, validates checksums, and attaches checksum/provenance release assets before package publication.
  • Adds a built-wheel CI smoke test outside the source checkout.

Local verification: pytest -q (21 passed), pyright (0 errors), strict MkDocs build, workflow YAML parse, reproducible two-environment wheel build, Twine validation, and installed-wheel CLI smoke all passed.

Opened as WIP because independent review and Forgejo CI evidence are still required. No tag, release, deploy, or registry upload was performed.

Implements HUI-016 and HUI-020 on signed commit `f77752dabf40adf8d83db68ee8ae0b6ff94c66aa`. - Fails closed on clean checkout, committed release signer, signed `v<version>` tag, target SHA/version agreement, and a successful exact-SHA tag CI run. - Locks frontend/backend, compares two clean-environment wheel builds, validates checksums, and attaches checksum/provenance release assets before package publication. - Adds a built-wheel CI smoke test outside the source checkout. Local verification: `pytest -q` (21 passed), pyright (0 errors), strict MkDocs build, workflow YAML parse, reproducible two-environment wheel build, Twine validation, and installed-wheel CLI smoke all passed. Opened as WIP because independent review and Forgejo CI evidence are still required. No tag, release, deploy, or registry upload was performed.
Harden package release verification
Some checks failed
Docs site / Validate docs build (pull_request) Successful in 1m28s
Python CI / Validate formatting, typing, and tests (pull_request) Failing after 6m12s
Python CI / Build source and wheel distributions (pull_request) Has been skipped
Docs site / Publish docs to mehalter.page (pull_request) Has been skipped
f77752dabf
Bind published release wheel to reproducibility check
All checks were successful
Docs site / Validate docs build (pull_request) Successful in 1m33s
Python CI / Validate formatting, typing, and tests (pull_request) Successful in 6m10s
Docs site / Publish docs to mehalter.page (pull_request) Has been skipped
Python CI / Build source and wheel distributions (pull_request) Successful in 6m22s
bf8d256668
Author
Owner

Closing without merge because the owner cancelled the code-security-audit-2026-07 campaign. This does not revert previously merged work.

Closing without merge because the owner cancelled the `code-security-audit-2026-07` campaign. This does not revert previously merged work.
clawlter closed this pull request 2026-07-14 08:15:45 -04:00
All checks were successful
Docs site / Validate docs build (pull_request) Successful in 1m33s
Python CI / Validate formatting, typing, and tests (pull_request) Successful in 6m10s
Required
Details
Docs site / Publish docs to mehalter.page (pull_request) Has been skipped
Python CI / Build source and wheel distributions (pull_request) Successful in 6m22s
Required
Details

Pull request closed

Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
clawlter/hermes-usage-insights!28
No description provided.