Skip to content

batch B audit: highest trust Gold surfaces #14

Description

@Riverbraid

Status

BATCH B AUDIT INVENTORY ITEM / PARTIALLY REMEDIATED

Scope

Batch B covers:

  • Riverbraid-Safety-Gold
  • Riverbraid-Refusal-Gold
  • Riverbraid-Crypto-Gold
  • Riverbraid-GPG-Gold
  • Riverbraid-Manifest-Gold
  • Riverbraid-Governance-Gold
  • Riverbraid-Harness-Gold

Confirmed public entry strengths

  • Safety, Refusal, Crypto, GPG, Manifest, and Harness have README role and evidence boundary language.
  • Refusal and Harness link back to Evaluation Kit or Documentation.
  • Manifest explicitly states GitHub Pages is disabled and verification is repository based, not deployment based.
  • Most package scripts point to verify.mjs or feature-flow verification.

Current finding state

  1. Riverbraid-Governance-Gold README and workflow target were remediated. The README was normalized and a bounded audit_final.js scaffold check was added. Execution evidence remains required in Riverbraid-Governance-Gold#1.
  2. Riverbraid-Harness-Gold/runtime-binding.js and src/runtime-binding.js were patched to remove CI GPG skip behavior and shell-string GPG execution. Execution evidence remains required in Riverbraid-Harness-Gold#5.
  3. Riverbraid-GPG-Gold still has a GPG-secret workflow surface. This is not inherently wrong, but secret validity and workflow evidence remain manual or evidence-gated.
  4. Several workflows still use ubuntu-latest and tag-pinned actions rather than pinned runner/image/action digests or SHA-pinned actions.
  5. Safety and Harness workflow-versus-package verifier path differences still need package-script-level classification.
  6. Safety has a legacy script that prints a verified-style message. That should not be treated as verification evidence unless separately bounded.
  7. Central community health coverage now exists in .github for SECURITY.md, CONTRIBUTING.md, and SUPPORT.md. Per-repo root coverage and root LICENSE coverage remain policy decisions and audit items.

Search-limited non-findings

Search did not return visible hits in Batch B for common private key markers, GitHub token markers, AWS secret marker, npm token marker, pull_request_target, permissions: write-all, secrets.GITHUB_TOKEN, pipe-to-shell patterns, or common nondeterminism markers.

This is search-limited and does not prove absence across history, settings, artifacts, dependencies, release assets, or unindexed surfaces.

Required follow-up

  • Run execution evidence for Governance Gold and Harness Gold patched paths.
  • Confirm whether GPG workflows still need fresh CI secrets.
  • Classify workflow verifier path versus package verifier path for Safety and Harness.
  • Decide whether to add per-repo SECURITY, CONTRIBUTING, SUPPORT, and LICENSE surfaces beyond central .github coverage.
  • Preserve registry freshness lock until explicit registry succession gate exists.

Boundary

This issue records audit inventory only.
It does not claim Batch B is secure, complete, production ready, externally audited, or free of defects.
It does not mutate registry, verifier behavior, protocol, hash, seal, manifest, tag, or release state.

Metadata

Metadata

Assignees

No one assigned

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions