docs(agents): the manifest shape is also a provenance signal #40
No reviewers
Labels
No labels
waiting-on-julian
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
jlxq0/jmap-mcp!40
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "docs/manifest-shape-as-provenance"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A second use for the index-versus-single-manifest fact, beside avoiding a false rollback. Refs #14. Docs only, no version bump.
Every image this repository's CI builds is an index, because the
buildctlpath attaches an attestation. So a single-manifestjmap-mcpimage did not come out of.forgejo/workflows/ci.yml.v0.2.5andv0.2.6are single manifests, which is a third independent signal beside:org.opencontainers.image.revisionto readcargo, allfailure, nodockerjob at allNone of the three shares a failure mode with the others, which is what makes them corroboration rather than one observation counted three times.
Gate:
cargo +1.93.0 fmt --all --checkrc=0,cargo +1.93.0 test --all-features --lockedrc=0, 197 passed.