Skip to content

Draft approval signing design#27

Merged
SSBrouhard merged 1 commit into
mainfrom
codex/approval-signing-design
Jun 10, 2026
Merged

Draft approval signing design#27
SSBrouhard merged 1 commit into
mainfrom
codex/approval-signing-design

Conversation

@SSBrouhard

Copy link
Copy Markdown
Owner

Summary

  • add docs/approval_signing_design.md as the v0.3.0 design gate for asymmetric, out-of-domain approval signatures (Asymmetric out-of-domain approval signatures #24)
  • define the key-isolation boundary, signed payload, public-key handling, fail-closed verification states, compatibility modes, CLI sketch, and acceptance gates
  • link approval signing to the evidence integrity boundary from Add tamper-evident evidence ledger and verification command #2 without changing runtime behavior
  • add a minimal pointer from docs/evidence.md while preserving current HMAC/advisory wording

Follow-up issues

Validation

  • .venv/bin/python scripts/vmga_release_check.py
  • .venv/bin/python -m compileall src tests scripts integrations
  • .venv/bin/python -m pytest -q
  • git diff --check
  • forbidden-vocabulary scan for the sourcebook terms called out in the task

Design/docs only. No crypto code and no behavior change.

@SSBrouhard SSBrouhard force-pushed the codex/approval-signing-design branch from 45f9a02 to dd6b05d Compare June 10, 2026 09:34
@SSBrouhard SSBrouhard merged commit 80b5aae into main Jun 10, 2026
5 checks passed
@SSBrouhard SSBrouhard deleted the codex/approval-signing-design branch June 10, 2026 09:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant