Milestones
List view
Production Sigstore fidelity hardening: real Fulcio chain walk + temporal validity + SCT/CT-log, standard Rekor SET + Merkle inclusion proof, real X.509 parsing, TUF-distributed trust root. Converts v1's honest-stub crypto (operator-supplied + fake stack) into real public-good Sigstore verification. Parent epic #205; includes deferred #107 (Rekor v2), #197 (cosign v3 interop).
No due date•0/7 issues closedTransparency and compliance layer on top of the signing pipeline: in-toto/DSSE attestation engine (attach + verify), CycloneDX SBOM attach + discovery as signed OCI referrers, SLSA provenance attach + policy-driven verify (builder pinning), OSV.dev vulnerability scan of cargo-auditable binaries at install, publisher CI guides, threat-model reference. Nothing here changes the trust decision a default install makes (milestone 'Signing & Trust v1' ships that); this answers: what is in this binary, who built it, is it known-vulnerable.
No due date•0/3 issues closedEnd-to-end keyless Sigstore signing and verification for OCX packages: real Sign/VerifyPipeline via sigstore-rs (Rekor v1 + TUF trust root day one; Rekor v2 as delta), registry referrers capability handling with clean errors, identity-pinned [trust.policy] in ocx.toml, offline/air-gapped trust-root story, policy-gated auto-verify on install/pull, cosign v3 interop. Secure-defaults story: signed after push, verified by default, typosquatting defeated. Defers: Notation, PKCS#11/YubiKey, private TUF root, rebuilders, SLSA VSA, cosign pre-3.0 consumer compat.
No due date•2/10 issues closedFirst wave of AI integration: bundle agentskills.io-compatible skills with packages and ship an MCP server (ocx mcp serve) for registry browsing. Excludes plugin/rule distribution — deferred pending security review.
No due date•0/8 issues closed