Skip to content

Implement the provenance ledger + conductor ssot verify + attestation #9

Description

@ronimoe

Context

The committed JSONL provenance ledger (agent id, model, params, plan-hash->code-hash) is designed but not implemented. It is a rebuildable projection of GitHub.

Scope

  • Append the ledger on land; conductor ssot trace/verify (every released commit -> issue+changeset; every closed issue -> a release).
  • OIDC-bound verdict signatures; optional Sigstore/Rekor.

Acceptance

conductor ssot verify flags broken links; the ledger rebuilds from GitHub metadata.

Seam

new tools/conductor/ssot.py; verifier.py verdict records; ADR-0010.

Metadata

Metadata

Assignees

No one assigned

    Labels

    operational-hardeningWiring real GitHub/CI/registry behind the engine seams

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions