v0.1.0-alpha1 claim boundary, and reproducibility stated per artifact - #10
Merged
Merged
Conversation
ISEDRAF Technical Preview — Linux Host Assurance & Evidence Engine.
The README now states what is claimed and, explicitly, what is not: no GA or
production readiness, not all Linux distributions, no ARM64 certification, no
organizational compliance, no CIS or ISO 27001 mapping, no NIS2/DORA, no PDF
reports, no privileged production Mode A. A technical preview is a thing you can
install, inspect and verify. It is not a thing to run a compliance programme on.
Reproducibility is stated per artifact, because the three are not interchangeable:
source tarball bit-for-bit reproducible across tested builders
.deb bit-for-bit reproducible across tested builders
.rpm package semantics and payload reproducible; NOT claimed
byte-for-byte across rpm toolchain versions
rpm 4 writes a gzip payload and rpm 6 writes zstd. That is toolchain variation, not
a different ISEDRAF payload — BUILDTIME was identical on both builders, so
SOURCE_DATE_EPOCH works across toolchains. No 'Reproducible Builds' badge will
appear without a qualifier naming which formats actually have byte-identical proof.
The repository topology is recorded in the decisions register: this public
repository receives a sanitized export, private engineering history is never
exported, and a release or tag is a separate owner-authorized act.
Implements: D-86, D-88, D-90, D-110, GOV-001
Assisted-by: Claude (claim alignment)
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
States what the technical preview claims and — explicitly — what it does not. Reproducibility is stated per artifact rather than as one word, because the source tarball and
.debhave byte-identical proof across tested builders and the.rpmdoes not: rpm 4 writes gzip, rpm 6 writes zstd. No unqualified reproducible-builds badge.