Skip to content

fix(release): attest the V3 manifest asset - #186

Merged
Rwanbt merged 1 commit into
mainfrom
fix/attest-v3-manifest
Sep 17, 2026
Merged

Rwanbt merged 1 commit into
mainfrom
fix/attest-v3-manifest

Conversation

@Rwanbt

@Rwanbt Rwanbt commented Sep 17, 2026

Copy link
Copy Markdown
Owner

Closes #185. Found during the v2.5.0 publication qualification: subject-path covered the wheel, sdist and lifecycle bundle but not the manifest, so the published ainative-release-v3.json of v2.5.0 has no build-provenance attestation (bundle attested, manifest not).

  • subject-path now includes dist/*.json with a WHY comment.
  • docs/RELEASING.md states the manifest is attested like every published asset.
  • docs/MULTIFORGE-QUALIFICATION.md records the v2.5.0 gap as a known limitation: the manifest stays covered by SHA256SUMS and GitHub's asset metadata (the anchor the runtime actually verifies), and the published v2.5.0 assets are never replaced retroactively.
  • Next release must show a verifiable manifest attestation (gh attestation verify).
  • No other publication behavior changes.

@Rwanbt
Rwanbt merged commit 52c05cc into main Sep 17, 2026
52 checks passed
@Rwanbt
Rwanbt deleted the fix/attest-v3-manifest branch September 17, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] The release workflow does not attest the V3 manifest asset

1 participant