registrystack / registrystack/registry-stack
Signed audit checkpoint and external anchoring primitives (evidence-grade roadmap)
- Vorherrschende Sprache
- Rust
- Sterne
- 2
- Forks
- 0
- Ø Merge
- 2 Std. 55 Min.
- Gemergte PRs (30 T.)
- 130
Beschreibung
Migrated from: https://github.com/jeremi/registry-platform/issues/56
Original author: @jeremi
Source repository: `jeremi/registry-platform`
Source issue: `#56`
Source labels: post-1.0
Source milestone/release intent: _none_
Target area/path: `products/platform; crates/registry-platform-*`
## Issue
[redacted private/internal deployment detail during migration]
Both products already stub toward this: relay posture exposes `audit.checkpoint_status` / `verification_status: "not_supported"` and warns `relay.audit_checkpoint_unavailable`; the hash-chain and keyed-integrity primitives live in `registry-platform-audit`. The shared checkpoint/anchoring primitive belongs here so relay and notary adopt one implementation.
[redacted private/internal deployment detail during migration]
**Acceptance:** checkpoint generation + verification round-trip tests; posture fields flip from `not_supported`; continuity-break detection has a failing test before implementation.
_Note: one or more private/internal references were redacted during migration._
## Migration Metadata
- Migrated to the public monorepo on 2026-06-25.
- Source title, body, labels, milestone/release intent, and pre-migration discussion were preserved where available.
- Code-grounded audit note: Posture fields exist, but signed checkpoints and external anchoring remain unsupported/planned.
- Private/internal references, secrets, and obvious deployment-only details were redacted instead of copied forward.
Beitragsleitfaden
Rechercherichtung
Beginne mit dem Lesen der vorhandenen Hash-Chain- und Keyed-Integrity-Primitiven in `registry-platform-audit` und untersuche anschließend `products/platform` sowie `crates/registry-platform-*` auf `audit.checkpoint_status`, `verification_status` und `relay.audit_checkpoint_unavailable`. Erstelle vor der Implementierung einen fehlschlagenden Test für eine Kontinuitätsunterbrechung. Als erledigt gilt die Aufgabe, wenn die Round-Trip-Tests für die Generierung und Verifizierung signierter Checkpoints bestehen und die Posture-Felder nicht mehr `not_supported` melden.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- rust
- Bereich
- backend, cryptography, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Ruhig
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 42/100