Skip to content

Track: v1 engineering and supply-chain hardening (v1_engineering_hardening_20260714) #44

Description

@edithatogo

Parent programme: #38

Objective

Qualify untrusted-artifact handling, compatibility, performance, dependencies, CI, reproducibility, SBOM/provenance, rollback, and vulnerability response for v1.

Acceptance

  • Threat model covers every externally controlled input and release boundary.
  • Property, fuzz, hostile-input, mutation, and resource-limit tests meet frozen thresholds.
  • Supported-platform, compatibility, performance, and reproducibility matrices pass.
  • SBOMs, checksums, provenance, rollback, and residual-risk evidence are release-ready.

Local spec and plan are authoritative.

Dependencies

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ci-requiredRequires local checks and GitHub Actions monitoring.conductor-trackIssue mirrors a local Conductor track.github-projectGitHub Issues/Projects synchronization.hardeningSecurity, reliability, compatibility, and supply-chain hardeningreleaseProgram release orchestration and certification.v1-roadmapRaC Conformance v1.0 maturity and release programme

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions