Explain normalization and delivery with portable client evidence - #102
Merged
Merged
Conversation
… build environment (#101)
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved scope-validation and release-verification workflow issues remain.
Review effort: Lite
Findings: 2
Open (2)
What changed in this PR
This PR adds portable normalization and delivery evidence, v2 record collection, offline HTML reporting, release-note validation, and installed-binary verification.
Changes:
- Records provenance, scope, checks, and immutable delivery batches.
- Adds validated evidence recovery and self-contained reports.
- Adds demos, documentation, CI coverage, and release tooling.
| File | Summary |
|---|---|
tools/verify-release.py |
Verifies published assets and native demos. |
tools/verify-release_test.py |
Tests release verification boundaries. |
tools/release-notes.py |
Selects authored release notes. |
tools/release-notes_test.py |
Tests release-note policies. |
tools/README.md |
Documents demos and verification. |
tools/demo-record/run.py |
Extends record demonstrations. |
tools/demo-record/README.md |
Documents record reports. |
tools/demo-normalization-evidence/table.json |
Provides normalization demo data. |
tools/demo-normalization-evidence/run.py |
Runs normalization evidence demo. |
tools/demo-normalization-evidence/rio.yaml |
Configures normalization demo. |
tools/demo-normalization-evidence/README.md |
Documents normalization demo. |
tools/demo-normalization-evidence/bom.json |
Provides normalization fixture data. |
tools/demo-dtrack-tls/run.py |
Checks report behavior. |
tools/demo-dtrack-tls/README.md |
Documents TLS/report demo. |
tools/demo-delivery/integration/setup_test.py |
Tests integration setup safeguards. |
tools/demo-delivery/integration/README.md |
Documents disposable integration services. |
tools/demo-delivery/integration/compose.yaml |
Defines pinned integration services. |
tools/demo-client-record/rio.yaml |
Configures client-record demo. |
tools/demo-client-record/README.md |
Documents client handoff demo. |
tools/demo-client-record/fixtures/services/alpha-server/pom.xml |
Provides service fixture metadata. |
tools/demo-client-record/fixtures/services/alpha-server/bom.json |
Provides service SBOM fixture. |
tools/demo-client-record/fixtures/clients/beta-client/pom.xml |
Provides client fixture metadata. |
tools/demo-client-record/fixtures/clients/beta-client/bom.json |
Provides client SBOM fixture. |
tools/demo-batch-evidence/run.py |
Runs batch evidence demo. |
tools/demo-batch-evidence/rio.yaml |
Configures batch evidence demo. |
tools/demo-batch-evidence/README.md |
Documents batch recovery. |
tools/demo-batch-evidence/fixtures/worker.json |
Provides worker fixture. |
tools/demo-batch-evidence/fixtures/app.json |
Provides application fixture. |
tools/demo-artifact-sets/run.sh |
Demonstrates artifact-set inspection. |
tools/ci-changes_test.py |
Tests demo change detection. |
README.md |
Documents the evidence workflow. |
internal/transform/transform.go |
Adds resolution provenance types. |
internal/transform/purl/p2/table.go |
Captures mapping metadata and digests. |
internal/transform/purl/p2/provenance_test.go |
Tests provenance behavior. |
internal/transform/purl/p2/p2.go |
Propagates repair provenance. |
internal/transform/purl/p2/p2_test.go |
Updates repair expectations. |
internal/sbom/document.go |
Adds identity assertions. |
internal/index/scope.go |
Validates normalization scope and checks. |
internal/index/normalization.go |
Validates normalization ledgers. |
internal/index/normalization_test.go |
Tests ledger validation. |
internal/index/index.go |
Adds index evidence extensions. |
internal/gate/gate.go |
Records requirement evaluations. |
internal/evidence/write.go |
Protects publication sources. |
internal/evidence/types.go |
Extends evidence document types. |
internal/evidence/report/write.go |
Writes report output. |
internal/evidence/report/text.go |
Renders terminal reports. |
internal/evidence/report/sync_windows.go |
Provides Windows report synchronization. |
internal/evidence/report/sync_unix.go |
Provides Unix report synchronization. |
internal/evidence/report/model_test.go |
Tests report models. |
internal/evidence/report/html.go |
Renders self-contained HTML reports. |
internal/evidence/preflight.go |
Adds bounded record parsing. |
internal/evidence/parse.go |
Parses v1 and v2 records. |
internal/evidence/marshal.go |
Marshals versioned records. |
internal/evidence/coverage.go |
Computes batch exclusions. |
internal/evidence/collect.go |
Supports bounded evidence collection. |
internal/evidence/batch.go |
Collects immutable batch sources. |
internal/delivery/verify.go |
Validates index extensions. |
internal/delivery/runner/submit.go |
Supports assigned attempt IDs. |
internal/delivery/runner/batch_evidence.go |
Builds completion evidence. |
internal/delivery/record/store.go |
Persists journal identities. |
internal/delivery/record/assigned_attempt_test.go |
Tests assigned attempts. |
internal/delivery/json.go |
Handles future extensions. |
internal/delivery/batchrecord/types.go |
Defines batch descriptors and completions. |
internal/delivery/batchrecord/sync_windows.go |
Provides Windows batch synchronization. |
internal/delivery/batchrecord/sync_unix.go |
Provides Unix batch synchronization. |
internal/delivery/batch_plan.go |
Captures delivery scope. |
internal/delivery/batch_plan_test.go |
Tests captured batch scope. |
internal/cli/testdata/rcp-client.cdx.json |
Updates identity evidence fixture. |
internal/cli/record.go |
Adds v2 collection and reporting. |
internal/cli/record_v2_test.go |
Tests v2 collection. |
internal/cli/record_report.go |
Adds the report command. |
internal/cli/record_report_test.go |
Tests report safety and integrity. |
internal/cli/record_inspect.go |
Preserves raw record bytes. |
internal/cli/normalize.go |
Records normalization evidence. |
internal/cli/normalization_scope_test.go |
Tests effective scope and checks. |
internal/cli/normalization_evidence.go |
Builds change ledgers and provenance. |
internal/cli/normalization_evidence_test.go |
Tests normalization evidence. |
internal/cli/delivery_evidence.go |
Automates evidence collection. |
internal/cli/deliver.go |
Adds evidence delivery flow. |
internal/cli/client_demo_test.go |
Verifies client demo fixtures. |
docs/releases/v0.6.0.md |
Adds authored release notes. |
docs/output.md |
Documents evidence schemas and limits. |
docs/manifest.md |
Documents scope and checks. |
docs/enrichment.md |
Documents enrichment ledgers. |
docs/cli.md |
Documents evidence and report commands. |
AGENTS.md |
Documents release-note policy. |
.github/workflows/verify-release.yaml |
Adds published-release verification. |
.github/workflows/release.yaml |
Integrates authored release notes. |
.github/workflows/ci.yaml |
Adds demos and integration checks. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+179
to
+180
| if (c.Mode != "warn" && c.Mode != "fail") || c.ComponentScope != "all components including nested" || c.ComponentCount < a.Components || c.ComponentRequirements == nil || c.Evaluations == nil || c.GraphCheck != "dangling-dependency-references" || c.GraphFindings != len(a.IntegrityFindings) { | ||
| return bad() |
Comment on lines
+27
to
+35
| if not source.exists(): | ||
| if tuple(int(match[i]) for i in (1, 2, 3)) >= (0, 6, 0): | ||
| raise ValueError("authored notes required for " + tag) | ||
| if not output.is_file() or not output.read_bytes().strip(): | ||
| raise ValueError("historical generated notes missing or empty") | ||
| print("NOTES: historical generated-note policy for " + tag) | ||
| return | ||
| if source.is_symlink() or not source.is_file(): | ||
| raise ValueError("authored notes must be a regular file") |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Clients previously had to reconstruct repair decisions and intended delivery coverage from separate workspace files. This change makes
rio normalize --gate fail && rio deliver --evidence target/rio/record.jsonproduce one portable, validated account of selection, changes, checks, attempts and evidence gaps.rio record reportrenders the same facts as self-contained offline HTML.Validation at
7736e894c5befba404f7377c9654305a349af8f4:go mod tidy -diff, build, vet, full race suite, installer tests, all CI Python suites and every installed-binary demo passed locally (macOS arm64, static release-equivalent build). Exact-head CI includes native Linux/macOS/Windows and disposable Distribution/Zot and DTrack 5.1.1/PostgreSQL18. Real HTTP/HTTPS integration includes trusted CA and explicit bypass through a test gateway; separate inventory observations are not native content-verification claims. Successful and partial HTML reports were reviewed at desktop and narrow widths without overflow or external requests. A fresh whole-branch review found a missing-journal publication collision; its failing regression and fix are included.The complete synthetic handoff covers uplift, repair, unresolved mapping, inherited enrichment, exclusions, partial/lost responses, failed gate/override, actual process interruption, explicit retry/reconcile snapshots, source deletion, relocation, tamper refusal and secret-canary checks. Authored note and release-verifier tests pass; actual v0.5.0 download verification exercised the new verifier tooling. The forthcoming release and notification remain tracked in #94/#101 and are not claimed here.
Records remain unsigned consistency evidence; full payload/input retention, artifact-to-SBOM binding, broader quality checks and Artifactory validation are separate scopes. #45 and #47 remain open.
Fixes #44
Fixes #95
Fixes #96
Fixes #97
Fixes #98
Fixes #99
Fixes #100
Related: #94, #101, #45, #47.