[CI-FU-10] ci: inventory and close remaining tool-provenance gaps
- Dominant language
- Go
- Stars
- 2
- Forks
- 0
- Avg merge
- 5h 49m
- Merged PRs (30d)
- 189
Description
Tracking ID: **CI-FU-10**
## Problem
Some CI tools and downloaded artifacts still rely on mutable tags, version strings, or checksums published beside the artifact. The repository should have a bounded inventory of remaining provenance gaps.
## Scope
- Inventory executable tools and containers downloaded by all workflows.
- Classify each as immutable/provenance-verified, checksum-only, mutable, or platform-managed.
- Propose small follow-up PRs for material gaps, prioritizing required and release-critical jobs.
- Do not duplicate CI-DN-04, CI-DN-05, CI-FU-08, or CI-FU-09.
## Acceptance
- The issue gains a checked inventory with evidence and explicit dispositions.
- Any implementation preserves least privilege and fails closed.
- Platform-managed actions are not replaced without a demonstrated security or reliability benefit.
This is an umbrella audit; implementations should remain small and independently reversible.
Contributor guide
No contributing guide indexed for this repository
Research direction
No specific files, tests, or entry points are named. Start by reviewing all repository workflows and the executable tools and containers they download, then record evidence and an explicit provenance disposition for each. Done means the checked inventory is complete and material gaps have independently reversible follow-up proposals.
Written by the indexing model from the issue text.
Assessment
- Domain
- ci-cd, security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100