d0ugal / d0ugal/graith

[CI-FU-10] ci: inventory and close remaining tool-provenance gaps

Open
#1,765 2 comments 0 reactions 0 assignees View on GitHub
dependencies enhancement next size: L testing
Dominant language
Go
Stars
2
Forks
0
Avg merge
5h 49m
Merged PRs (30d)
189

Description

Tracking ID: **CI-FU-10**

## Problem

Some CI tools and downloaded artifacts still rely on mutable tags, version strings, or checksums published beside the artifact. The repository should have a bounded inventory of remaining provenance gaps.

## Scope

- Inventory executable tools and containers downloaded by all workflows.
- Classify each as immutable/provenance-verified, checksum-only, mutable, or platform-managed.
- Propose small follow-up PRs for material gaps, prioritizing required and release-critical jobs.
- Do not duplicate CI-DN-04, CI-DN-05, CI-FU-08, or CI-FU-09.

## Acceptance

- The issue gains a checked inventory with evidence and explicit dispositions.
- Any implementation preserves least privilege and fails closed.
- Platform-managed actions are not replaced without a demonstrated security or reliability benefit.

This is an umbrella audit; implementations should remain small and independently reversible.

Contributor guide

No contributing guide indexed for this repository

Research direction

No specific files, tests, or entry points are named. Start by reviewing all repository workflows and the executable tools and containers they download, then record evidence and an explicit provenance disposition for each. Done means the checked inventory is complete and material gaps have independently reversible follow-up proposals.

Written by the indexing model from the issue text.

Assessment

Domain
ci-cd, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.