Status
BATCH B AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED
Scope
Batch B covers:
- Riverbraid-Safety-Gold
- Riverbraid-Refusal-Gold
- Riverbraid-Crypto-Gold
- Riverbraid-GPG-Gold
- Riverbraid-Manifest-Gold
- Riverbraid-Governance-Gold
- Riverbraid-Harness-Gold
Confirmed public entry strengths
- Safety, Refusal, Crypto, GPG, Manifest, and Harness have README role and evidence boundary language.
- Refusal and Harness link back to Evaluation Kit or Documentation.
- Manifest explicitly states GitHub Pages is disabled and verification is repository based, not deployment based.
- Most package scripts point to
verify.mjs or feature-flow verification.
Current finding state
Riverbraid-Governance-Gold README and workflow target were remediated. The README was normalized and a bounded audit_final.js scaffold check was added. Execution evidence remains required in Riverbraid-Governance-Gold#1.
Riverbraid-Harness-Gold/runtime-binding.js and src/runtime-binding.js were patched to remove CI GPG skip behavior and shell-string GPG execution. Execution evidence remains required in Riverbraid-Harness-Gold#5.
Riverbraid-GPG-Gold still has a GPG-secret workflow surface. This is not inherently wrong, but secret validity and workflow evidence remain manual or evidence-gated.
- Several workflows still use
ubuntu-latest and tag-pinned actions rather than pinned runner/image/action digests or SHA-pinned actions.
- Safety and Harness workflow-versus-package verifier path differences still need package-script-level classification.
- Safety has a legacy script that prints a verified-style message. That should not be treated as verification evidence unless separately bounded.
- Central community health coverage now exists in
.github for SECURITY.md, CONTRIBUTING.md, and SUPPORT.md. Per-repo root coverage and root LICENSE coverage remain policy decisions and audit items.
Search-limited non-findings
Search did not return visible hits in Batch B for common private key markers, GitHub token markers, AWS secret marker, npm token marker, pull_request_target, permissions: write-all, secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.
This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.
Required follow-up
- Run execution evidence for Governance Gold and Harness Gold patched paths.
- Confirm whether GPG workflows still need fresh CI secrets.
- Classify workflow verifier path versus package verifier path for Safety and Harness.
- Decide whether to add per-repo SECURITY, CONTRIBUTING, SUPPORT, and LICENSE surfaces beyond central
.github coverage.
- Preserve registry freshness lock until explicit registry succession gate exists.
Boundary
This issue records audit inventory only.
It does not claim Batch B is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.
Status
BATCH B AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED
Scope
Batch B covers:
Confirmed public entry strengths
verify.mjsor feature-flow verification.Current finding state
Riverbraid-Governance-GoldREADME and workflow target were remediated. The README was normalized and a boundedaudit_final.jsscaffold check was added. Execution evidence remains required inRiverbraid-Governance-Gold#1.Riverbraid-Harness-Gold/runtime-binding.jsandsrc/runtime-binding.jswere patched to remove CI GPG skip behavior and shell-string GPG execution. Execution evidence remains required inRiverbraid-Harness-Gold#5.Riverbraid-GPG-Goldstill has a GPG-secret workflow surface. This is not inherently wrong, but secret validity and workflow evidence remain manual or evidence-gated.ubuntu-latestand tag-pinned actions rather than pinned runner/image/action digests or SHA-pinned actions..githubforSECURITY.md,CONTRIBUTING.md, andSUPPORT.md. Per-repo root coverage and rootLICENSEcoverage remain policy decisions and audit items.Search-limited non-findings
Search did not return visible hits in Batch B for common private key markers, GitHub token markers, AWS secret marker, npm token marker,
pull_request_target,permissions: write-all,secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.
Required follow-up
.githubcoverage.Boundary
This issue records audit inventory only.
It does not claim Batch B is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.