Skip to content

Conversation

@markthom-as
Copy link
Collaborator

Summary\n- require cosign key + certificate identity + OIDC issuer pinning for cosign verification\n- add verify/run regression tests for the tightened contract\n- sync canonical v0 spec files from provenact-spec\n\n## Validation\n- cargo test -p provenact-cli --test pack_sign --test run

@markthom-as markthom-as merged commit 7c8f30f into main Feb 10, 2026
5 checks passed
@markthom-as markthom-as deleted the codex/security-consistency-hardening-2026-02-10 branch February 10, 2026 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant