Skip to content

Verify content-addressed Issue lifecycle preflight evidence #608

Description

@proerror77

Parent

#455

What to build

Add the read-only verify operation for the bundle produced by #607. It validates the exact file set, canonical JSON, SHA-256 sidecars, schema and repository/controller scope, API and page inventory, object counts, and default-branch identity. Optional live verification independently re-reads GitHub and rejects any mutable or provenance drift.

Acceptance criteria

  • Local verification rejects missing, extra, symlinked, non-canonical, tampered, or digest-mismatched bundle entries.
  • Manifest schema, repository/controller/target/exclusions, API/media versions, page inventory, counts, and preflight identity are validated fail-closed.
  • Live verification re-fetches the complete Capture content-addressed Issue lifecycle preflight evidence #607 graph and rejects default-branch, pagination/header, Issue/PR metadata, relationship, comment/event, check, or status drift.
  • Focused tests prove valid independent readback, tamper rejection, scope/schema mismatch rejection, incomplete pagination rejection, and zero GitHub writes.

Blocked by

#607 must merge first.

Out of scope

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

enhancementNew feature or requestready-for-agentFully specified and safe for an autonomous agent

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions