Skip to content

[REVIEW ONLY] Audit public export from bran-dev 3cde6f0 - #2

Draft
1wgrumph wants to merge 1 commit into
agent/review-bran-dev-3cde6f0-basefrom
main
Draft

[REVIEW ONLY] Audit public export from bran-dev 3cde6f0#2
1wgrumph wants to merge 1 commit into
agent/review-bran-dev-3cde6f0-basefrom
main

Conversation

@1wgrumph

Copy link
Copy Markdown
Contributor

Review-only comparison — do not merge

This draft PR exists to expose the exact diff that was already synchronized to public main in commit 696ba97e15ce571e4e65e4b1acf75a95b0710b41.

The base branch is intentionally pinned to the pre-sync public commit 152183f2c38b938ec79d44253de1a3986e7edc8d. The head is current public main. Merging this PR would only advance the historical review branch; it must not be used as another publication action.

Provenance

  • Canonical source repository: alphazede/bran-dev
  • Canonical source commit: 3cde6f06586d41b96cfad0da57015ed8919b9322
  • Public synchronization commit: 696ba97e15ce571e4e65e4b1acf75a95b0710b41
  • Public parent before synchronization: 152183f2c38b938ec79d44253de1a3986e7edc8d
  • Export drift guard: exact match, 109 exported files

Diff under review

Four public files changed:

  • .bran-export.json
  • .bran/policy.yaml
  • README.md
  • docs/integrations/agent-setup.md

Git reports 135 insertions and 17 deletions.

Verification rerun

The following were rerun from clean bran-dev commit 3cde6f0 before opening this review:

  • pinned BRAN SHA-256 verification
  • bran check <bran-dev> bran-strict
  • ./tools/cutover/publish-hygiene.sh
  • ./tools/ci/check.sh --full
  • conformance gate
  • security gate
  • controlled performance benchmarks
  • sealed-release self-test
  • python3 tools/ci/public_export.py check --public-dir /home/spectre/alphazede/bran
  • git diff --check 152183f..696ba97

All completed successfully. These checks are evidence for review, not permission to merge or publish.

Owner review requested

Please inspect the four-file diff for behavioral, documentation, policy, and public-boundary defects. If defects are found, repair them in bran-dev, export a new candidate branch, and open a normal draft PR targeting public main.

Rule for future BRAN publication

Every future bran-devalphazede/bran synchronization must:

  1. originate from a reviewed, committed bran-dev revision;
  2. generate the public snapshot through the approved exporter;
  3. push the snapshot to a non-default public branch;
  4. open a draft PR targeting public main;
  5. include exact source/export SHAs and validation evidence;
  6. receive owner review before merge; and
  7. verify the exact merged/installed artifact end-to-end before any release or publication claim.

Direct synchronization to public main is prohibited.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants