Documentation
¶
Overview ¶
Package releasegate verifies one manifest-selected, immutable Git release tree. It is experimental evidence only; it never builds, publishes, or promotes a release.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Allowance ¶
Allowance names an inert, unshipped fixture blob. It never exempts an archive member or an artifact-inventory member from scanning.
type ArchiveMember ¶
type ArchiveReader ¶
type ArchiveReader interface {
Members([]byte) ([]ArchiveMember, error)
}
type BuildTarget ¶
type Checks ¶
type Checks struct {
Parity Status `json:"parity"`
Safety Status `json:"safety"`
Performance Status `json:"performance"`
Packaging Status `json:"packaging"`
CorvintDogfood Status `json:"corvintDogfood"`
BeamfallDogfood Status `json:"beamfallDogfood"`
}
Checks is deliberately complete for GPK-V0-026. This experimental gate can only decide safety; all other evidence remains visible, never implied.
type Evidence ¶
type Evidence struct {
Path string `json:"path"`
BlobOID string `json:"blobOid"`
BlobSHA256 string `json:"blobSha256"`
EnclosingMembers []string `json:"enclosingMembers,omitempty"`
MemberPath string `json:"memberPath,omitempty"`
MemberSHA string `json:"memberSha256,omitempty"`
SpanStart int `json:"spanStart"`
SpanEnd int `json:"spanEnd"`
SpanSHA256 string `json:"spanSha256"`
Line int `json:"line,omitempty"`
Column int `json:"column,omitempty"`
}
Evidence locates exactly the bytes which produced a finding. Spans are zero-based half-open byte offsets in the named blob or archive member. EnclosingMembers lists, outermost first, the archive member paths that contain MemberPath's archive when the member is nested.
type Manifest ¶
type Manifest struct {
ArtifactInventory []string `json:"artifactInventory"`
ArtifactModes map[string]string `json:"artifactModes"`
ArtifactSHA256 string `json:"artifactSha256"`
Allowances []Allowance `json:"allowances"`
BuildPackages []string `json:"buildPackages"`
BuildTargets []BuildTarget `json:"buildTargets"`
CorePackages []string `json:"corePackages"`
AnalyzerPackages []string `json:"analyzerPackages"`
PluginPackages []string `json:"pluginPackages"`
CoreSizeCeiling int64 `json:"coreSizeCeilingBytes"`
PluginSizeCeilings map[string]int64 `json:"pluginSizeCeilingBytes"`
PluginArtifacts map[string][]string `json:"pluginArtifacts"`
AnalyzerSizeCeilings map[string]int64 `json:"analyzerSizeCeilingBytes"`
}
Manifest is canonical only when decoded from ManifestPath in the exact scanned tree. Report records both the manifest blob identities and the resolved commit/tree identities, binding policy and scan without a self-referential manifest hash. ArtifactInventory is the complete accepted shipping inventory, sorted and unique. BuildPackages are the selected production package roots.
type Options ¶
type Options struct {
Root string
Commit string
ManifestPath string // slash-separated path in the scanned commit tree
GitExecutable string // externally supplied absolute executable path
GitSHA256 string // externally pinned executable digest
PolicyPath string // externally supplied absolute policy path
PolicySHA256 string // externally pinned policy digest
}
type Report ¶
type Report struct {
Commit string `json:"commit"`
Tree string `json:"tree"`
ManifestPath string `json:"manifestPath"`
ManifestBlobOID string `json:"manifestBlobOid"`
ManifestBlobSHA256 string `json:"manifestBlobSha256"`
GitExecutable string `json:"gitExecutable,omitempty"`
GitSHA256 string `json:"gitSha256,omitempty"`
Checks Checks `json:"checks"`
Findings []Finding `json:"findings"`
}
type TarArchive ¶
type TarArchive struct{}
func (TarArchive) Members ¶
func (TarArchive) Members(content []byte) ([]ArchiveMember, error)
type ZipArchive ¶
type ZipArchive struct{}
func (ZipArchive) Members ¶
func (ZipArchive) Members(content []byte) ([]ArchiveMember, error)