githubnext / githubnext/gh-aw-cao

[eu-cra-compliance:conformity-release-evidence] github/gh-aw CRA conformity and release evidence

Closed
#12,219 0 comments 0 reactions 0 assignees View on GitHub
eu-cra-compliance eu-cra-compliance:conformity-release-evidence
Dominant language
JavaScript
Stars
3
Forks
1
Avg merge
49m
Merged PRs (30d)
837

Description

github/gh-aw release evidence is partially present, but CRA-critical traceability and declaration artifacts are not verified from the checkout. The release workflow shows strong supply-chain controls (SBOM generation, checksum verification, Defender scan, provenance-enabled container build), yet key market-release evidence remains missing or requires human legal/compliance judgment.

**Action:** Release/compliance owners for `github/gh-aw` SHOULD review the named gaps below and add a 👍 only after confirming the full release-version traceability, documentation matrix, conformity register, release-gate evidence, gaps, and human decisions are complete.

`repo: github/gh-aw @ 038128d2b80c4da07f794576d1031d176178677a`

### Assessed release/version
- Target release/version: `NOT_ASSESSED`
- Repository commit assessed: `038128d2b80c4da07f794576d1031d176178677a`
- Verification date: `2026-09-16`

### Verified regulatory sources
| Topic | Status | Evidence | Source |
| --- | --- | --- | --- |
| CRA legal instrument exists | EVIDENCE_SUFFICIENT | Official text for Regulation (EU) 2024/2847 retrieved. | source: { instrument: "Regulation (EU) 2024/2847", provision: "whole instrument", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| CRA timeline baseline | EVIDENCE_SUFFICIENT | Commission CRA page retrieved and contains 10 Dec 2024 entry into force, 11 Sep 2026 Article 14 reporting obligations, 11 Dec 2027 full application, and 27 Jul 2026 guidance. The 11 Jun 2026 conformity-assessment-body milestone was not confirmed in fetched text and remains INCOMPLETE. | source: { instrument: "European Commission CRA policy page", provision: "implementation timeline", authority: "non-binding" } — https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act — verified 2026-09-16 |
| ENISA guidance entry point reachable | EVIDENCE_SUFFICIENT | ENISA homepage retrieved as official non-binding source entry point. | source: { instrument: "ENISA website", provision: "official guidance entry point", authority: "non-binding" } — https://www.enisa.europa.eu/ — verified 2026-09-16 |

### Technical documentation matrix
| Requirement / topic | Status | Observed evidence | Source |
| --- | --- | --- | --- |
| Product identity and intended purpose | EVIDENCE_SUFFICIENT | `README.md` identifies `gh-aw` as GitHub Agentic Workflows, a GitHub CLI extension for AI-powered repository automation in Markdown workflows. | source: { instrument: "Regulation (EU) 2024/2847", provision: "technical documentation / product identification", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Economic-operator contact evidence | EVIDENCE_SUFFICIENT | `SECURITY.md` provides coordinated disclosure contact `opensource-security[@]github.com`; repository ownership is GitHub. Manufacturer/importer role for CRA purposes is HUMAN_REVIEW_REQUIRED. | source: { instrument: "Regulation (EU) 2024/2847", provision: "manufacturer obligations / reporting contact", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Versions / release floor traceability | EVIDENCE_SUFFICIENT | `.github/aw/releases.json` defines `minimumVersion` and `minRecommendedVersion` as `v0.65.3`. Release workflow computes semver tags from existing releases. | source: { instrument: "Regulation (EU) 2024/2847", provision: "technical documentation / version traceability", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Dependency and component inventory | EVIDENCE_SUFFICIENT | `go.mod` lists direct and transitive dependencies; `SECURITY.md` states SPDX and CycloneDX SBOMs are generated on every release; release workflow generates and uploads both. | source: { instrument: "Regulation (EU) 2024/2847", provision: "technical documentation / components and dependencies", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Vulnerability handling process | EVIDENCE_SUFFICIENT | `SECURITY.md` provides coordinated disclosure process; `CONTRIBUTING.md` documents `.grype.yaml` risk-acceptance handling for unfixed upstream vulnerabilities. | source: { instrument: "Regulation (EU) 2024/2847", provision: "vulnerability handling", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Secure build / integrity checks | EVIDENCE_SUFFICIENT | Release workflow validates container SHA pins, verifies binary checksums before Defender scan, enables `provenance: mode=max` for container build, and requests `attestations: write`. | source: { instrument: "Regulation (EU) 2024/2847", provision: "secure development and production", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Technical documentation retention control | GAP_FOUND | No checked-in evidence found for retaining technical documentation and EU Declaration of Conformity for at least 10 years after market placement or support period, whichever is longer. | source: { instrument: "Regulation (EU) 2024/2847", provision: "retention obligations", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Support period / end-of-support disclosure | GAP_FOUND | No decisive checkout evidence found for published support period or end-of-support date for released versions. | source: { instrument: "Regulation (EU) 2024/2847", provision: "user information / support period", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| EU Declaration of Conformity draft and signatory control | GAP_FOUND | No checked-in DoC draft, signatory review control, or language/availability control evidence found. | source: { instrument: "Regulation (EU) 2024/2847", provision: "EU declaration of conformity", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| CE marking / labeling evidence | NOT_ASSESSED | No approval conclusion made; no decisive release labeling evidence found in checkout. | source: { instrument: "Regulation (EU) 2024/2847", provision: "CE marking", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |

### Conformity evidence register
| Claim | Status | Evidence | Source |
| --- | --- | --- | --- |
| Harmonised-standard presumption of conformity established | GAP_FOUND | No harmonised standard claim with Official Journal citation for Regulation (EU) 2024/2847 was found in reviewed checkout evidence. | source: { instrument: "Regulation (EU) 2024/2847", provision: "presumption of conformity / harmonised standards", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Product classification and conformity route are determined | HUMAN_REVIEW_REQUIRED | Repository purpose suggests developer tooling, but CRA scope, economic-operator role, commercial vs non-commercial FOSS treatment, substantial modification, and any important/critical class decision require explicit human review. | source: { instrument: "Regulation (EU) 2024/2847", provision: "scope and classification", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Release workflow preserves security evidence | EVIDENCE_SUFFICIENT | Release path includes SBOM generation, artifact upload, checksum validation, malware scan, and provenance-enabled image build. | source: { instrument: "Regulation (EU) 2024/2847", provision: "secure development / technical documentation", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |
| Residual-risk decisions are recorded for accepted vulnerabilities | EVIDENCE_SUFFICIENT | `.grype.yaml` records scoped risk acceptances with reason text for unfixed upstream image vulnerabilities. Human review is still required to confirm CRA adequacy of these records for the assessed release. | source: { instrument: "Regulation (EU) 2024/2847", provision: "risk assessment and residual risk", authority: "binding" } — https://eur-lex.europa.eu/eli/reg/2024/2847/oj — verified 2026-09-16 |

### Release-gate matrix
| Gate | Status | Evidence |
| --- | --- | --- |
| Product/release identity traceable to commit and version inputs | EVIDENCE_SUFFICIENT | Git commit assessed; semver release-tag computation and minimum-version metadata present. |
| Build and release approvals | INCOMPLETE | Manual environment approval exists (`gh-aw-actions-release`), but authorized approver roster and approval records were not accessible from checkout. |
| Artifact hashes and integrity | EVIDENCE_SUFFICIENT | Release workflow verifies `checksums.txt` before Windows Defender scan. |
| Provenance / attestation linkage | INCOMPLETE | Workflow requests attestation permissions and build provenance for container image, but no retrieved signed attestation artifact or verification record was available in checkout. |
| SBOM linkage to released artifacts | INCOMPLETE | Workflow generates SPDX/CycloneDX SBOMs and uploads artifacts, but assessed release asset set and artifact-retention evidence were not accessible from checkout. |
| Post-release support ownership | HUMAN_REVIEW_REQUIRED | Maintainers are listed in `CODEOWNERS`, but CRA post-release support ownership and economic-operator accountability need human confirmation. |

### Gaps and inaccessible evidence
- `GAP_FOUND`: no checked-in support period or end-of-support disclosure.
- `GAP_FOUND`: no checked-in EU Declaration of Conformity draft, signatory, or publication control evidence.
- `GAP_FOUND`: no checked-in technical-documentation retention control for the 10-year / support-period rule.
- `GAP_FOUND`: no verified harmonised-standard Official Journal citation for CRA presumption of conformity.
- `INCOMPLETE`: release-specific approvals, generated SBOM artifacts, signed attestations, and final release assets were not established from the target checkout alone.
- `INCOMPLETE`: official confirmation of the 11 June 2026 conformity-assessment-body milestone was not established from fetched source text.

What's working: the release workflow already captures several high-value software supply-chain controls that many projects add later, especially checksum verification before malware scan and provenance-enabled container builds.

### Human-review decisions
1. Compliance/legal owner MUST determine CRA scope, economic-operator role, and whether this repository is assessed as commercial product software or another category.
2. Product/release owner MUST determine the candidate conformity-assessment route; this record does not select one.
3. Compliance owner MUST decide whether existing `.grype.yaml` risk-acceptance records are sufficient CRA residual-risk evidence for the assessed release.
4. Release owner MUST verify the actual release’s SBOM artifacts, provenance/attestations, approvals, and retention records in access-controlled systems.
5. Authorized signatory reviewer MUST decide whether a DoC draft is ready and controlled; this record does not approve it.

### Human Acceptance
A non-bot reviewer SHOULD add a 👍 reaction only after reviewing the complete release-version traceability, documentation matrix, conformity register, release-gate evidence, gaps, inaccessible evidence, and named human decisions.

### Control Plane
- Correlation ID: `35124602775-324`
- Central repository: `githubnext/gh-aw-cao`
- Control plane run URL: https://github.com/githubnext/gh-aw-cao/actions/runs/35124602775

> Generated by [:clipboard: EU CRA / Conformity](https://github.com/githubnext/gh-aw-cao/actions/runs/35125081646) · pi · gpt54 · 35.6 AIC · ⊞ 9.9K · [◷](https://github.com/search?q=repo%3Agithubnext%2Fgh-aw-cao+is%3Aissue+%22gh-aw-workflow-call-id%3A+githubnext%2Fgh-aw-cao%2Feu-cra-compliance-conformity-release-evidence%22&type=issues)
> - [x] expires on Oct 16, 2026, 5:03 PM UTC

Contributor guide

Open the contributing guide

Research direction

Start by reviewing README.md, SECURITY.md, .github/aw/releases.json, go.mod, CONTRIBUTING.md, .grype.yaml, and the release workflow evidence named in the matrix. Compare the checkout with the listed CRA gaps and incomplete release gates. Done means the release-version traceability, documentation matrix, conformity register, release-gate evidence, retention controls, and required human decisions are complete and reviewed.

Written by the indexing model from the issue text.

Assessment

Tech stack
github-actions
Domain
documentation, release, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.