Skip to content

docs(release): record v0.13.0 reproducibility proof#483

Merged
jeremi merged 1 commit into
mainfrom
codex/beta17-reproducibility-proof
Jul 25, 2026
Merged

docs(release): record v0.13.0 reproducibility proof#483
jeremi merged 1 commit into
mainfrom
codex/beta17-reproducibility-proof

Conversation

@jeremi

@jeremi jeremi commented Jul 25, 2026

Copy link
Copy Markdown
Member

Summary

  • record the public v0.13.0 P/T binary and OCI reproducibility proof
  • bind the proof to the annotated tag, release workflow, and published image digests
  • state the exact scope and exclusions of the reproducibility claim

Verification

  • manifest and versioned-docset validation
  • import-map and release source-model validation
  • 156 release and source-model tests
  • retained P1/P2/T1/T2 binary and image-input equality
  • exact P and T OCI comparisons and P-to-T rootfs comparisons
  • workflow artifact SHA-256 and byte equality
  • published OCI application-manifest, ordered-layer, provenance, package-linkage, and anonymous-pull verification
  • public-boundary scan
  • git diff --check

@jeremi
jeremi enabled auto-merge (squash) July 25, 2026 11:17
@jeremi
jeremi merged commit e51fc5e into main Jul 25, 2026
28 checks passed
@jeremi
jeremi deleted the codex/beta17-reproducibility-proof branch July 25, 2026 11:19

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: d47dda66fc

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

tag, locked dependencies, and the pinned release builder image declared in
`.github/workflows/release.yml`.

## v0.13.0 Linux amd64 Binary and OCI Image Proof

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Add the required DCO sign-off

The message for commit 7a349cf7a47240d2b5cc27ad38567b86b397dcc9 has no Signed-off-by: trailer, so this commit violates the repository's mandatory DCO policy and must be recreated with a valid sign-off before merging.

AGENTS.md reference: AGENTS.md:L68-L70

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant