Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
Expand Up @@ -3,3 +3,4 @@
.reposentinel.toml -text whitespace=cr-at-eol
.reposentinel-baseline.json -text whitespace=cr-at-eol
policy/repo-sentinel-authority/v1/* -text whitespace=cr-at-eol
policy/repo-sentinel-authority/v2/* -text whitespace=cr-at-eol
1,439 changes: 1,439 additions & 0 deletions .reposentinel-baseline.json

Large diffs are not rendered by default.

2 changes: 2 additions & 0 deletions .reposentinel.toml
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,6 @@ ignore_globs = [
".reposentinel-baseline.json",
"reports/markdownlint-debt.txt",
"reports/placeholder-audit.txt",
"policy/repo-sentinel-authority/v1/**",
"policy/repo-sentinel-authority/v2/**",
]
9,580 changes: 9,580 additions & 0 deletions policy/repo-sentinel-authority/v2/baseline.json

Large diffs are not rendered by default.

91 changes: 91 additions & 0 deletions policy/repo-sentinel-authority/v2/coverage-policy.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,91 @@
{
"approved_exclusions": [
{
"mode": "100644",
"path": ".reposentinel-baseline.json",
"reason": "config_ignore",
"sha256": "8eff61c98f62d54b7280517967e6f9f8e66ffb2d18f5d4acbb9de63565a01669"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/baseline.json",
"reason": "config_ignore",
"sha256": "0b6e8641d58a8a4c927d6dd610562d6f6e40bddb7cb1dd0f7c42c103ae3193b5"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/coverage-policy.json",
"reason": "config_ignore",
"sha256": "36b544546949b64e83bde547ca861f03446e7ef1f3321439795a90ffc8a6b0de"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/dependencies.json",
"reason": "config_ignore",
"sha256": "a8acbdf5ba63d28ac2e8d6940d7618eb2bde1851696cbdd31ae07a7666037074"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/epoch.json",
"reason": "config_ignore",
"sha256": "25e08c1051ad0e8d3137728435dc1dec57b52bf3d7497cb82c51d1739a1ba82e"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/protected-manifest.json",
"reason": "config_ignore",
"sha256": "307fc1e7c57879bc82ba9aab658d1ac318214addd16dd125057c5996a79bf466"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/scanner-config.toml",
"reason": "config_ignore",
"sha256": "69d0c0d8748e8c113aa31f63c82992633b666a61c0eb60a4298138ee885dea33"
},
{
"mode": "100644",
"path": "policy/repo-sentinel-authority/v1/suppression-manifest.json",
"reason": "config_ignore",
"sha256": "98265ad3389adbf19f55f1141b58151a7e35ad0dcf6a43dfc2b94848db0aec1d"
},
{
"mode": "100644",
"path": "reports/markdownlint-debt.txt",
"reason": "config_ignore",
"sha256": "85c81f3abf8dce8b1e08e95ceca33243adbd6829f2c4db586d1f23a152cb6197"
},
{
"mode": "100644",
"path": "reports/placeholder-audit.txt",
"reason": "config_ignore",
"sha256": "53228461cdc4e9db92612944d30152efff3ce50a80e850bdb6cdc82641e77a13"
}
],
"effective_ignore_globs": [
".reposentinel-baseline.json",
"%TEMP%",
"*.egg-info",
".coverage",
".mypy_cache",
".nox",
".pytest_cache",
".ruff_cache",
".tox",
".venv",
".venv-*",
"__pycache__",
"build",
"coverage",
"dist",
"dist-*",
"htmlcov",
"node_modules",
"venv",
"reports/markdownlint-debt.txt",
"reports/placeholder-audit.txt",
"policy/repo-sentinel-authority/v1/**",
"policy/repo-sentinel-authority/v2/**"
],
"max_text_file_size": 1048576,
"schema_version": 1
}
9 changes: 9 additions & 0 deletions policy/repo-sentinel-authority/v2/dependencies.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,9 @@
{
"runtime_dependencies": [],
"scanner": {
"distribution": "repo-sentinel-lite",
"version": "0.8.1",
"wheel_sha256": "0a949a4d00c6e6ae37eba60a6cb74e4e15bc3ec5fce2f1d4c99aa0ef309b36e3"
},
"schema_version": 1
}
25 changes: 25 additions & 0 deletions policy/repo-sentinel-authority/v2/epoch.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
{
"component_sha256": {
"baseline.json": "8eff61c98f62d54b7280517967e6f9f8e66ffb2d18f5d4acbb9de63565a01669",
"coverage-policy.json": "679da3c4f5188367842ad55f25e9f00c0af34dff97fa8c9b528f1d51b243a7cb",
"dependencies.json": "a8acbdf5ba63d28ac2e8d6940d7618eb2bde1851696cbdd31ae07a7666037074",
"protected-manifest.json": "787da55b0104d81d6b4404a93baf562b64c2a337c9ce94f7dff88fe4a59bcb79",
"scanner-config.toml": "296b51421202609a4b770d868cd1026a2aa26e884e66dff759516679e63b73e4",
"suppression-manifest.json": "6e8dbc24956284b763d74fe25fda579f49838a8e1e18d6665739e70697345506"
},
"policy_epoch": "repo-sentinel-authority-v2",
"portable_path_policy_version": "portable-v1",
"runtime": {
"architecture": "x86_64",
"implementation": "cpython",
"os_family": "Linux",
"python_version": "3.12.3"
},
"scanner": {
"artifact_sha256": "0a949a4d00c6e6ae37eba60a6cb74e4e15bc3ec5fce2f1d4c99aa0ef309b36e3",
"distribution": "repo-sentinel-lite",
"version": "0.8.1"
},
"schema_version": 1,
"semantic_worker_policy_version": "commit-authoritative-v1"
}
94 changes: 94 additions & 0 deletions policy/repo-sentinel-authority/v2/protected-manifest.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,94 @@
{
"entries": [
{
"mode": "100644",
"path": ".gitattributes",
"sha256": "69c12dff31af0dd49817c0f38898cfc0304fb33d95f0bcf093f0208c0c849a59"
},
{
"mode": "100644",
"path": ".github/workflows/markdown-lint.yml",
"sha256": "d9a175b811a904f7b4e9da79e356980f557c8656cfa4ea81744bc86ecb241175"
},
{
"mode": "100644",
"path": ".github/workflows/markdownlint-debt.yml",
"sha256": "286c57901506054dfcdd5ba5425c3e851a6201ee43ffec95db765b579d99a64a"
},
{
"mode": "100644",
"path": ".github/workflows/placeholder-audit.yml",
"sha256": "71fffc8b84e38ab3bf95b6497dafb32a3f3ec563fef8e5894a234123989c495c"
},
{
"mode": "100644",
"path": ".github/workflows/repo-sentinel-gate.yml",
"sha256": "bff70a88960b96d445be7149258a4b2c5d8fef1126ecce6bb6520b794efd1931"
},
{
"mode": "100644",
"path": ".reposentinel-baseline.json",
"sha256": "8eff61c98f62d54b7280517967e6f9f8e66ffb2d18f5d4acbb9de63565a01669"
},
{
"mode": "100644",
"path": ".reposentinel.toml",
"sha256": "296b51421202609a4b770d868cd1026a2aa26e884e66dff759516679e63b73e4"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_acquire.py",
"sha256": "6133a969ccad41394113775c872d35403b94f1d80926fab95948a123ad8f54e9"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_authoritative.py",
"sha256": "33b7fe73fa798b212177e9f4a5064ee0845aa19f50a8df29d0fcd85451b95220"
},
{
"mode": "100755",
"path": "scripts/repo_sentinel_authority_bootstrap.sh",
"sha256": "cdeb5b89adb4005ff1c9ab4bae5f113ffb9a725164a18b4af05a1325c0e69f30"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_authority_controller.py",
"sha256": "52fd52bab5a6f821e874c39c6cf28298610a7854b07468c854158a0f41a032d7"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_commit_authoritative.py",
"sha256": "4743536cfc55b777afd06b4dc1d50c5c0bfe7dcc3bd7a80849ad0cdf4a18ed67"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_gate.py",
"sha256": "79be642d1aa1b464b377115ef8d02175f82a793f7f242b714efe35e4f97a190f"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_materialize.py",
"sha256": "05fd0b6448fdb3b6c52969700d6a9a19e4790c7c78343af09aebb37d0bc5c0ed"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_policy_bundle.py",
"sha256": "0b8ef28aeba391dac366f38bb5ce4903132acfcb89359f01067a773b12ad4386"
},
{
"mode": "100644",
"path": "scripts/repo_sentinel_reader.py",
"sha256": "3fc587a12847d58bd78d4168a3a959293c76928f60a6ccfcae5d1fb5d8e36ef0"
},
{
"mode": "100644",
"path": "scripts/test_repo_sentinel_integration.py",
"sha256": "ae67bd08f03c0a0877c5c078f32ec2e91b72fb0ad768cdadcf3688e8afe142a2"
}
],
"namespaces": [
".github/actions/",
".github/workflows/"
],
"schema_version": 1
}
7 changes: 7 additions & 0 deletions policy/repo-sentinel-authority/v2/scanner-config.toml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
ignore_globs = [
".reposentinel-baseline.json",
"reports/markdownlint-debt.txt",
"reports/placeholder-audit.txt",
"policy/repo-sentinel-authority/v1/**",
"policy/repo-sentinel-authority/v2/**",
]
15 changes: 15 additions & 0 deletions policy/repo-sentinel-authority/v2/suppression-manifest.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,15 @@
{
"entries": [
{
"mode": "100644",
"path": "tests/test_repo_sentinel_authoritative.py",
"sha256": "203e057697436bd2db73313ec8d27e7564d04684218a3c2e51608f9066a420e2"
},
{
"mode": "100644",
"path": "tests/test_repo_sentinel_commit_authoritative.py",
"sha256": "80656d8990f2daa58e9b0aff8a8c0b1ee2da408f6d970467beac64f8e596c44e"
}
],
"schema_version": 1
}
4 changes: 3 additions & 1 deletion tests/test_repo_sentinel_policy_contracts.py
Original file line number Diff line number Diff line change
Expand Up @@ -254,13 +254,15 @@ def test_v2_build_terminates_without_writing_digest_back_to_runtime(self) -> Non
RUNTIME,
policy_selector="v2",
)
self.assertEqual(
{item.name for item in root.iterdir()}, set(policy.BUNDLE_FILENAMES)
)
after = {path: (ROOT / path).read_bytes() for path in RUNTIME_SOURCES}

self.assertEqual(before, after)
self.assertTrue(
all(digest.encode("ascii") not in data for data in after.values())
)
self.assertFalse((ROOT / "policy/repo-sentinel-authority/v2").exists())

def test_runtime_has_no_policy_bundle_digest_back_edge_symbol(self) -> None:
for path in RUNTIME_SOURCES:
Expand Down
Loading