ci(trust): OpenSSF Scorecard + SBOM + Sigstore signed releases#1141
Open
gHashTag wants to merge 3 commits into
Open
ci(trust): OpenSSF Scorecard + SBOM + Sigstore signed releases#1141gHashTag wants to merge 3 commits into
gHashTag wants to merge 3 commits into
Conversation
Contributor
|
📓 NotebookLM Notebook linked to this PR
This notebook contains session context, decisions, and artifacts for this work. |
Contributor
PR DashboardGenerated at: 2026-06-15 07:49:38 UTC
Summary
Seal Status
|
This was referenced Jun 15, 2026
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
- scorecard.yml: weekly Scorecard analysis with SARIF upload - sbom.yml: SPDX SBOM generation on release via syft - sign-release.yml: cosign/sigstore signing of release artifacts Closes #1141
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
…d, June 2026 intel - fix(bootstrap): regression double-ref in HashMap::get (line 4202) - fix(bootstrap): 3 remaining unwrap/expect to safe error handling - fix(bootstrap): formula_eval.rs evaluate() arity mismatch (1 arg, not 2) - fix(clippy): ASCII check chars().all() to is_ascii() - fix(clippy): tri crate docs, trios-bridge HeaderValue cfg(test) import - feat(specs): specs/math/igla_primitives.t27 — softmax, matmul, RoPE, RMS norm, sacred opcode embed - feat(specs): specs/igla/race/yosys.t27 — equivalence checking + SVA assertion emission - feat(specs): specs/igla/race/eda.t27 — OpenROAD PPA feedback + phi-weighted scoring - feat(specs): specs/igla/race/backend.t27 — Booth-encoded multiplier elimination pass - docs: COMPETITIVE_POSITIONING_IGLA.md updated with June 2026 threats: Alpha-RTL, RTLScout, StepPRM-RTL, Veri-Sure, EdgeRazor, FormalRTL EXTREME - docs: README.md + NOW.md — IGLA spec directory expanded Closes #1141 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
- Report for Loop 12 IGLA CODER / IGLA RACE - Regression fix, panic elimination, clippy cleanup, June 2026 intel - Cooperation variants for Loop 13 Closes #1141 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
…026 intel - fix(cli): final signal handler unwraps/expects in tri/src/main.rs - feat(specs): specs/igla/coder/prm.t27 — Process Reward Model with step-level verifiable rewards (syntax, lint, sacred compliance, simulation, synthesis, reference match) and phi-weighted scoring - docs: COMPETITIVE_POSITIONING_IGLA.md updated with 5 new threats: EffiSkel, RLVR, LLM4RTL, Interaction Tree Semantics for RISC-V, OrpQuant; PRM added as differentiator #2 - docs: README.md broken links fixed (README_RU.md, CLARA-PREPARATION-PLAN) - docs: Wave Loop Report Loop 13 Closes #1141 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
- docs/COMPETITIVE_POSITIONING_IGLA.md: 7 new competitors tracked: HierSVA (arXiv:2606.13706), CHIPCRAFTBRAIN (arXiv:2604.19856), FunPRM (arXiv:2601.22249), Unsupervised PRM (arXiv:2605.10158), E8 Zenodo (AIMS Ghana), Gray Mereon System (arXiv:2604.00255) - docs/COMPETITIVE_POSITIONING_IGLA.md: new Physics/Sacred Geometry section - docs: batch fix broken internal markdown links (RESEARCH_CLAIMS.md, AGENTS_ALPHABET.md, NOW.md, TASK_PROTOCOL.md, PUBLICATION_AUDIT.md, GITHUB_RING_ISSUES, etc.) — 94 → 66 remaining - Weak spot audit: 41 unwraps in compiler.rs verified as test-only (all inside #[cfg(test)] blocks); zero production panic vectors Closes #1141 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
gHashTag
pushed a commit
that referenced
this pull request
Jun 17, 2026
- Loop 14 report: compiler panic audit, 7 new competitors, 28 link fixes - Cooperation variants for Loop 15 Closes #1141 Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This was referenced Jun 19, 2026
This was referenced Jun 28, 2026
This was referenced Jul 5, 2026
Closed
Owner
Author
|
Closing stale PR — clean-up. Reopen if still relevant. |
Contributor
|
📓 NotebookLM Notebook linked to this PR
This notebook contains session context, decisions, and artifacts for this work. |
This was referenced Jul 6, 2026
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Цель — быстрый прирост «доверенности» (trustworthiness) без затрат
Внедряет три бесплатных GitHub Actions workflow, повышающих верифицируемую безопасность цепочки поставок. Это сильный, конкретный аргумент для грантовых заявок (ФСИ / Сколково) и соответствует ожиданиям ГОСТ Р 56939-2024 (РБПО) и требованиям аудита компонентов для реестра отечественного ПО.
Что добавлено
scorecard.ymlmaster, еженедельно (Пн 06:17 UTC),branch_protection_rulesbom.ymlmaster, релиз, ручной запускsign-release.ymlПринципы
permissions: read-all/read, повышение только на уровне job.Бейдж для README (после первого прогона)
Проверка подписи релиза