Skip to content
This repository was archived by the owner on Sep 5, 2026. It is now read-only.

docs: document doctor/trust commands + commit the missing PROVENANCE.md - #13

Merged
dcondrey merged 2 commits into
mainfrom
docs/trust-commands
Jun 28, 2026
Merged

docs: document doctor/trust commands + commit the missing PROVENANCE.md#13
dcondrey merged 2 commits into
mainfrom
docs/trust-commands

Conversation

@dcondrey

Copy link
Copy Markdown
Owner

Answers "is this documented?" — partly it wasn't, and surfaced a pre-existing bug.

What was undocumented

Pre-existing bug this fixes

PROVENANCE.md was never in the repo. A global ~/.config/git/ignore rule for PROVENANCE.md silently kept it out, so the two README links to ./PROVENANCE.md were dead on GitHub. Force-added it (content is the public provenance spec — Why/Implemented/Standards/Roadmap/Community, scanned for secrets) so the links resolve. It now also carries the trust-anchor + rotation section.

Not touched

CHANGELOG is git-cliff–generated from the conventional commits; the hardening + features land there on the next release automatically.

dcondrey added 2 commits June 28, 2026 13:57
The new doctor/trust commands and the TOFU trust anchor were only in THREAT-MODEL;
add them to the README Quick Start and the PROVENANCE implemented-features list so a
user reading the primary docs sees them. (CHANGELOG is git-cliff generated from the
conventional commits and picks these up on the next release.)
A global ~/.config/git/ignore rule for PROVENANCE.md kept this file out of the repo,
so the two README links to ./PROVENANCE.md were dead on GitHub. Force-add it (content
is the public provenance spec) so the links resolve; includes the trust-anchor section.
@dcondrey
dcondrey merged commit 4140511 into main Jun 28, 2026
2 checks passed
@dcondrey
dcondrey deleted the docs/trust-commands branch June 28, 2026 21:17
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant