Skip to content

Release blocker: restore exact-head validation after v2 hardening merge #17

Description

@ruvnet

Confirmed finding

PR #16 was merged as 945fc6fc, but every workflow group observed on its exact PR head ac9c2892 failed. The failed surface includes focused and full workspace validation, dependency audit, timing/security checks, compatibility, and performance qualification. No post-merge workflow receipt was available.

The source includes meaningful cryptographic and DAG hardening, but source plausibility is not a release receipt.

Acceptance criteria

  • Pass deterministic focused and full-workspace tests on the exact candidate commit.
  • Resolve dependency-audit findings or document affected-version reachability and a time-bounded remediation owner.
  • Run independent ML-KEM known-answer/interoperability vectors for every supported parameter set and negative tamper cases.
  • Pass timing-regression, fuzz/crash, license, secret-scan, clippy/format, Docker, CLI, WASM, and supported-platform compatibility gates.
  • Produce reproducible performance baselines with thresholds fixed before the candidate run.
  • Pin third-party GitHub Actions to verified full commit SHAs.
  • Keep release qualification fail closed; no skipped or failed required gate may be relabeled as acceptance.

No production vulnerability or exploitability claim is made here. Security-sensitive reproduction detail should use a private advisory if later confirmed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions