Run the configured pipeline and publish one compact receipt - #107
Merged
Merged
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Three moderate unresolved issues affect recovery safety, destination handling, and receipt accuracy.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
This PR makes bare rio execute the configured pipeline and publish compact, source-free receipts with isolated outputs, recovery support, delivery facts, and updated documentation.
Changes:
- Added receipt persistence, validation, reporting, checkpointing, and recovery.
- Integrated pipeline execution with OCI and DTrack delivery metadata.
- Updated demos, fixtures, documentation, tests, and CI for v0.7.0.
Review identified three moderate issues involving recovery safety, destination overlap handling, and inaccurate failed-run receipt coverage, plus two minor cleanup issues.
| File | Description |
|---|---|
tools/rio-context_test.py |
Tests structured run output paths. |
tools/demo-repair/run.sh |
Verifies normalization receipts. |
tools/demo-record/README.md |
Documents independent receipts. |
tools/demo-oci/README.md |
Documents OCI receipt behavior. |
tools/demo-oci/integration/README.md |
Clarifies journal and receipt evidence. |
tools/demo-normalization-evidence/run.py |
Validates normalization receipts. |
tools/demo-normalization-evidence/README.md |
Updates receipt workflow documentation. |
tools/demo-normalization-evidence/bom.json |
Exercises normalization behavior. |
tools/demo-enrichment/run.sh |
Consumes structured execution results. |
tools/demo-enrichment/README.md |
Updates enrichment demo instructions. |
tools/demo-dtrack-tls/README.md |
Documents TLS receipt behavior. |
tools/demo-delivery/README.md |
Documents one-command delivery. |
tools/demo-delivery/integration/README.md |
Documents delivery integration checks. |
tools/demo-context/run.sh |
Handles isolated output directories. |
tools/demo-context/README.md |
Documents failed receipts and run directories. |
tools/demo-client-record/README.md |
Introduces the compact receipt example. |
tools/demo-client-record/example/worker.cdx.json |
Provides a synthetic worker SBOM. |
tools/demo-client-record/example/SYNTHETIC-ONLY-key.pem |
Provides synthetic TLS key material. |
tools/demo-client-record/example/SYNTHETIC-ONLY-cert.pem |
Provides synthetic TLS certificate material. |
tools/demo-client-record/example/rio.yaml |
Configures the example pipeline. |
tools/demo-client-record/example/README.md |
Documents the runnable example. |
tools/demo-client-record/example/pipeline.json |
Defines example pipeline data. |
tools/demo-client-record/example/normalized/worker.cdx.json |
Provides normalized worker output. |
tools/demo-client-record/example/normalized/api.cdx.json |
Provides normalized API output. |
tools/demo-client-record/example/demo-ca.pem |
Provides example CA material. |
tools/demo-client-record/example/api.cdx.json |
Provides a synthetic API SBOM. |
tools/demo-batch-evidence/README.md |
Documents receipt recovery behavior. |
tools/demo-agent-integration/run.sh |
Updates the integration walkthrough. |
tools/demo-agent-integration/EVALUATION.md |
Updates runtime requirements. |
tools/demo-agent-integration/ci.sh |
Publishes receipts in CI. |
internal/receipt/tls_response_test.go |
Tests TLS response receipt facts. |
internal/receipt/sync_windows.go |
Provides Windows receipt synchronization. |
internal/receipt/sync_unix.go |
Provides Unix receipt synchronization. |
internal/receipt/report_test.go |
Tests receipt reporting. |
internal/receipt/paths.go |
Handles receipt and output paths. |
internal/receipt/consistency_test.go |
Tests receipt consistency. |
internal/receipt/bounds.go |
Defines receipt bounds. |
internal/manifest/manifest.go |
Adds output and gate configuration. |
internal/evidence/types.go |
Defines evidence types. |
internal/evidence/sync_windows.go |
Provides Windows evidence synchronization. |
internal/evidence/sync_unix.go |
Provides Unix evidence synchronization. |
internal/evidence/report/write.go |
Writes evidence reports. |
internal/evidence/report/html.go |
Renders evidence HTML. |
internal/evidence/preflight_test.go |
Tests evidence preflight behavior. |
internal/evidence/oci_bounds_test.go |
Tests OCI evidence bounds. |
internal/evidence/marshal.go |
Handles evidence serialization. |
internal/evidence/coverage.go |
Tracks evidence coverage. |
internal/delivery/types.go |
Defines delivery submission facts. |
internal/delivery/runner/submit.go |
Tracks delivery submissions. |
internal/delivery/runner/reconcile.go |
Supports delivery reconciliation. |
internal/delivery/runner/batch.go |
Runs delivery batches. |
internal/delivery/runner/batch_evidence.go |
Records batch delivery evidence. |
internal/delivery/record/recovery_test.go |
Tests delivery recovery. |
internal/delivery/record/record.go |
Defines delivery records. |
internal/delivery/record/capture.go |
Captures delivery state. |
internal/delivery/oci/transmission.go |
Tracks OCI transmissions. |
internal/delivery/oci/transmission_test.go |
Tests OCI transmission tracking. |
internal/delivery/oci/submit.go |
Submits OCI content. |
internal/delivery/oci/observe.go |
Observes OCI processing. |
internal/delivery/oci/integration_harness_test.go |
Tests OCI integration behavior. |
internal/delivery/oci/evidence.go |
Records OCI delivery facts. |
internal/delivery/oci/client.go |
Implements the OCI client. |
internal/delivery/dtrack/transmission_test.go |
Tests DTrack transmission tracking. |
internal/delivery/dtrack/submit.go |
Submits DTrack content. |
internal/delivery/dtrack/client.go |
Implements the DTrack client. |
internal/delivery/batchrecord/types.go |
Defines batch record types. |
internal/delivery/batchrecord/sync_windows.go |
Provides Windows batch synchronization. |
internal/delivery/batchrecord/sync_unix.go |
Provides Unix batch synchronization. |
internal/delivery/batch_plan.go |
Defines delivery batch planning. |
internal/cli/testdata/plan.json |
Provides CLI plan test data. |
internal/cli/run_output_test.go |
Tests pipeline run output. |
internal/cli/retired_record_test.go |
Tests retired record handling. |
internal/cli/resolve.go |
Resolves CLI inputs and paths. |
internal/cli/repair_demo_test.go |
Tests repair demonstrations. |
internal/cli/record_v2_test.go |
Tests version-two records. |
internal/cli/record_report.go |
Reports delivery records. |
internal/cli/record_report_test.go |
Tests record reporting. |
internal/cli/record_inspect.go |
Inspects records. |
internal/cli/record_exit_test.go |
Tests record command exits. |
internal/cli/reconcile_receipt.go |
Creates reconciliation receipts. |
internal/cli/receipt_growth_test.go |
Tests receipt growth limits. |
internal/cli/plan_test.go |
Tests CLI planning. |
internal/cli/oci_review_test.go |
Tests OCI review behavior. |
internal/cli/oci_fixture_test.go |
Provides OCI CLI fixtures. |
internal/cli/normalization_scope_test.go |
Tests normalization scope. |
internal/cli/normalization_evidence_test.go |
Tests normalization evidence. |
internal/cli/main_test.go |
Tests CLI entry behavior. |
internal/cli/exit_test.go |
Tests CLI exit behavior. |
internal/cli/enrichment_test.go |
Tests enrichment behavior. |
internal/cli/dtrack_tls_test.go |
Tests DTrack TLS behavior. |
internal/cli/delivery.go |
Integrates CLI delivery execution. |
internal/cli/delivery_test.go |
Tests CLI delivery. |
internal/cli/delivery_registry.go |
Registers delivery adapters. |
internal/cli/delivery_registry_test.go |
Tests delivery registration. |
internal/cli/delivery_reconcile.go |
Integrates delivery reconciliation. |
internal/cli/delivery_batch_test.go |
Tests delivery batching. |
internal/cli/context_test.go |
Tests CLI context handling. |
internal/cli/context_demo_test.go |
Tests context demonstrations. |
internal/cli/compact_record.go |
Builds compact records. |
internal/cli/compact_record_test.go |
Tests compact records. |
internal/cli/client_demo_test.go |
Tests client demonstrations. |
internal/cli/cli.go |
Defines root CLI behavior. |
internal/cli/attest_test.go |
Tests attestation behavior. |
internal/cli/artifact_sets_demo_test.go |
Tests artifact-set demonstrations. |
docs/releases/v0.7.0.md |
Documents the v0.7.0 release. |
docs/quick-start.md |
Updates quick-start guidance. |
docs/project.md |
Updates project architecture documentation. |
docs/manifest.md |
Documents manifest configuration. |
docs/enrichment.md |
Documents enrichment and failed receipts. |
docs/delivery.md |
Documents delivery and receipts. |
cmd/rio/nonetwork_test.go |
Tests offline package behavior. |
AGENTS.md |
Updates repository workflow guidance. |
.github/workflows/ci.yaml |
Runs receipt-focused CI checks. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This was referenced Sep 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Bare
rionow executes the pipeline inrio.yamland publishes one compact receipt covering consumed SBOMs, meaningful metadata changes, checks, destinations, submitted bytes, TLS and receiver acknowledgments. Runs have isolated output directories; standalone normalization, delivery, retry and reconciliation retain their own scope and prior references.The new
rio-run-receiptcontract replaces the previous client evidence bundle. Offline inspection/rendering validates bounded, source-free receipts; durable internal checkpoints support explicit recovery without replaying uploads. Ordinary failures retain failed/unattempted coverage, and publication never replaces an existing receipt. Native DTrack/OCI adapters distinguish actual body writes, HTTP acceptance, processing activity and content verification.README and v0.7.0 authored notes lead with a generated two-SBOM example (5,791 bytes), complete runnable download and offline HTML. Demos and supporting tools consume invocation-specific output paths.
Validation: full Go build/vet/race suite and tidy check; focused failure, interruption/recovery, TLS, gate consistency, terminal/HTML safety and size regressions; all 12 installed-binary demos; enabled context interoperability smoke and storyboard capture; Python, installer and release-helper checks. Existing native-platform and disposable real-service CI jobs must pass before merge; published-artifact/Homebrew verification follows release publication.
Fixes #106