Skip to content

feat: record plugin and policy digests on evidence - #97

Merged
ianmiell merged 1 commit into
mainfrom
feat/evidence-source-digests
Oct 1, 2026
Merged

ianmiell merged 1 commit into
mainfrom
feat/evidence-source-digests

Conversation

@ianmiell

@ianmiell ianmiell commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

Follows #96. Evidence now also carries:

  • _plugin_digest: for an OCI plugin, the registry digest its reference resolved to when the agent downloaded it; for a local binary, its SHA-256.
  • _policy_digest: for an OCI policy bundle, the registry digest its reference resolved to when downloaded. Not set for local directories (_policy_bundle_digest covers their content).

The agent looks the digest up with a registry HEAD before downloading and keeps it in .ccf-source.json beside the extracted files, so cached runs still report it. Extractions made before this change have no record, so their evidence carries only the source until they are downloaded again.

Tagged as v0.8.0-rc4.

🤖 Generated with Claude Code

Evidence now carries _plugin_digest and _policy_digest beside the source
props: the registry digest an OCI reference resolved to when it was
downloaded (kept in .ccf-source.json for cached runs), or a local plugin
binary's SHA-256.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 36ca2d6e-2908-4cd6-a5ec-07eb25693df3

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@ianmiell
ianmiell merged commit fe15a6b into main Oct 1, 2026
6 checks passed
@ianmiell
ianmiell deleted the feat/evidence-source-digests branch October 1, 2026 12:55
ccf-lisa Bot added a commit that referenced this pull request Oct 1, 2026
Conflicts in runner/result.go and cmd/agent.go: keep the shared ArtifactUploader,
WithArtifactUploader, WithPolicyPaths symlink resolution and WithEvidenceProps alongside
main's WithSources. Semantic integration (design 13.4): policy sources are keyed by the
exact path plugins receive, including an inline bundle's stable current/bundle path, and
an inline bundle records _policy_source = inline:<name> with the stored bundle's artifact
digest, or its tree digest when the bundle could not be stored.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants