supply-chain-release

Identity
A definition is named by its content, so this address is what a ticket pins and what a consumer checks against:
sha256-f2aa808ac68e7f6a7e79b347d3006b8bfdadd6b01d279547b5646603f6212b27
Shape
● built ⊢ version · commit · ✎ci · ⧉checksums/
│
├─▶ attested ⊢ artifact.digest · ✎ci · ⊙sbom · ⊙provenance
│ │
│ ┈▶ approved
├─▶ scanned ⊢ scan.result = clean · ✎ci · ⊙vulnerability-scan
│ │
│ ▼ approved ★ ⊢ ⋈ after attested, scanned approval = ship · ✎release-manager · ⚖ commit ≠ approval
└─▶ withheld ⊢ approval = hold · ✎release-manager
Roles to fill
Every role ships empty, so adopting a process never inherits
somebody else’s org chart. Name yours with tik roles add <role> <actor>.
ci— emptyrelease-manager— empty
Facts it records
| Path | Shape |
|---|---|
approval | [:enum :ship :hold] |
artifact.digest | [:string {:min 8}] |
commit | [:string {:min 7}] |
scan.result | [:enum :clean :findings] |
version | [:string {:min 1}] |
Stages
built
Reached when:
- the fact
versionstands - the fact
commitstands commitwas asserted by a member of thecirole- an artifact is attached whose path starts with
checksums/
Runbook: kb/runbooks/supply-chain-release-built.md
attested
Follows built.
Reached when:
- the fact
artifact.digeststands artifact.digestwas asserted by a member of thecirole- an attestation of
:sbomexists, no older thanP1D - an attestation of
:provenanceexists, no older thanP1D
Runbook: kb/runbooks/supply-chain-release-attested.md
scanned
Follows built.
Reached when:
- the fact
scan.resultequals:clean scan.resultwas asserted by a member of thecirole- an attestation of
:vulnerability-scanexists, no older thanP1D
Runbook: kb/runbooks/supply-chain-release-scanned.md
approved · sticky
Follows attested, scanned.
Once reached it stays reached: the fold carries it forward, so later evidence cannot take it away.
Reached when:
- the fact
approvalequals:ship approvalwas asserted by a member of therelease-managerrole- the facts
commitandapprovalcame from different people
Runbook: kb/runbooks/supply-chain-release-approved.md
withheld
Follows built.
Reached when:
- the fact
approvalequals:hold approvalwas asserted by a member of therelease-managerrole
Runbook: kb/runbooks/supply-chain-release-withheld.md
Take it
tik adopt processes/supply-chain-release.edn```
The definition and its runbooks are copied into your store, and the
publisher's signature travels with them when a key in your `actors`
verifies it.
Read the stages before you adopt: they say who has to sign what,
which is a decision about your organisation.