Skip to content

[REVIEW ONLY] Audit public export from bran-dev 3cde6f0 - #2

Closed
1wgrumph wants to merge 10 commits into
agent/review-bran-dev-3cde6f0-basefrom
main
Closed

[REVIEW ONLY] Audit public export from bran-dev 3cde6f0#2
1wgrumph wants to merge 10 commits into
agent/review-bran-dev-3cde6f0-basefrom
main

Conversation

@1wgrumph

Copy link
Copy Markdown
Contributor

Review-only comparison — do not merge

This draft PR exists to expose the exact diff that was already synchronized to public main in commit 696ba97e15ce571e4e65e4b1acf75a95b0710b41.

The base branch is intentionally pinned to the pre-sync public commit 152183f2c38b938ec79d44253de1a3986e7edc8d. The head is current public main. Merging this PR would only advance the historical review branch; it must not be used as another publication action.

Provenance

  • Canonical source repository: alphazede/bran-dev
  • Canonical source commit: 3cde6f06586d41b96cfad0da57015ed8919b9322
  • Public synchronization commit: 696ba97e15ce571e4e65e4b1acf75a95b0710b41
  • Public parent before synchronization: 152183f2c38b938ec79d44253de1a3986e7edc8d
  • Export drift guard: exact match, 109 exported files

Diff under review

Four public files changed:

  • .bran-export.json
  • .bran/policy.yaml
  • README.md
  • docs/integrations/agent-setup.md

Git reports 135 insertions and 17 deletions.

Verification rerun

The following were rerun from clean bran-dev commit 3cde6f0 before opening this review:

  • pinned BRAN SHA-256 verification
  • bran check <bran-dev> bran-strict
  • ./tools/cutover/publish-hygiene.sh
  • ./tools/ci/check.sh --full
  • conformance gate
  • security gate
  • controlled performance benchmarks
  • sealed-release self-test
  • python3 tools/ci/public_export.py check --public-dir /home/spectre/alphazede/bran
  • git diff --check 152183f..696ba97

All completed successfully. These checks are evidence for review, not permission to merge or publish.

Owner review requested

Please inspect the four-file diff for behavioral, documentation, policy, and public-boundary defects. If defects are found, repair them in bran-dev, export a new candidate branch, and open a normal draft PR targeting public main.

Rule for future BRAN publication

Every future bran-devalphazede/bran synchronization must:

  1. originate from a reviewed, committed bran-dev revision;
  2. generate the public snapshot through the approved exporter;
  3. push the snapshot to a non-default public branch;
  4. open a draft PR targeting public main;
  5. include exact source/export SHAs and validation evidence;
  6. receive owner review before merge; and
  7. verify the exact merged/installed artifact end-to-end before any release or publication claim.

Direct synchronization to public main is prohibited.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

1wgrumph and others added 9 commits August 7, 2026 09:22
Adds the okf-v0.2 compatibility profile, body-content ranking with unmatched-entity miss reporting, the shared digest validator, removal of hardcoded user-home paths with an enforcement check, and a test cleanup.

Source: alphazede/bran-dev 1938b3838e832e4e8035a86aab804257c6303124
Produced by tools/ci/public_export.py from a clean committed source.
Checks: fast SUCCESS, CodeQL (actions/python/rust) SUCCESS.
Records the shipped BRAN version (0.1.0) in the export receipt, read from the
committed CLI manifest so it is a deterministic function of the source commit.
Adds the Sigstore keyless release contract and workflow, and rewrites the README
around install steps, real command output, and the offline-or-connected split.
Fixes release build portability on Windows and macOS runners.
Rust xtask release packager, publish step, and pre-publish manifest validation.
Pin third-party release actions to commit SHAs.
Fixes Windows release packaging: the zip handle must be readable.
Build the Intel macOS target on an Apple Silicon runner.
Read the Rekor inclusion time from either cosign bundle shape.
@1wgrumph 1wgrumph closed this Aug 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants