You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Package publishing needs consistent release controls across AgenTrust. The repository consolidation is complete; this issue tracks the remaining safeguards sweep.
The TRACE cutover provides a verified starting point: reviewed PR #465, successful conformance publisher run, and PyPI 0.6.2. Its conformance-pypi environment currently has no required reviewers or deployment restrictions and allows administrator bypass, copied with explicit approval for cutover. That temporary configuration is not the desired organization-wide baseline.
Initial scope: agent-manifest, cmcp, ca2a, trace-spec (root library and conformance package), trace-registry, weight-custody-manifest, integrations (capture-core and trace-adapters), and agentrust-telemetry. Re-inventory active repositories to include any additional Python, npm, container or other package publishers. Archived source repositories should have no active publishing authority.
Completion criteria:
Inventory each package, publishing workflow, registry, release trigger and environment; link evidence and record an accountable primary and backup.
Agree and apply independent environment approval, prevent self-review where supported, restrict deployment refs to the intended release tags, and disable administrator bypass or document a reviewed exception. GitHub's required-reviewer list requires one listed approval, not all listed reviewers.
Verify two available package owners/operators and exact trusted-publisher repository/workflow/environment bindings. Remove obsolete bindings after replacement verification.
Require matching package/tag versions, successful tests and wheel/source or equivalent installed-artifact checks before publishing. Scope OIDC permissions to publishing jobs, pin external actions and preserve package-specific governance.
Separate build-only rehearsal from production publishing. Imran requested production PyPI only; do not require TestPyPI or dispatch production as a dry run.
Verify the resulting configuration through current settings and workflow evidence; record exceptions, owner and resolution.
Add a sustainable audit or release checklist so later workflow/environment drift is detected.
No credentials, recovery codes or secret values belong in this issue. A successful release by Imran proves the publisher path works; it does not prove backup-operator coverage.
Package publishing needs consistent release controls across AgenTrust. The repository consolidation is complete; this issue tracks the remaining safeguards sweep.
The TRACE cutover provides a verified starting point: reviewed PR #465, successful conformance publisher run, and PyPI 0.6.2. Its
conformance-pypienvironment currently has no required reviewers or deployment restrictions and allows administrator bypass, copied with explicit approval for cutover. That temporary configuration is not the desired organization-wide baseline.Initial scope: agent-manifest, cmcp, ca2a, trace-spec (root library and conformance package), trace-registry, weight-custody-manifest, integrations (capture-core and trace-adapters), and agentrust-telemetry. Re-inventory active repositories to include any additional Python, npm, container or other package publishers. Archived source repositories should have no active publishing authority.
Completion criteria:
No credentials, recovery codes or secret values belong in this issue. A successful release by Imran proves the publisher path works; it does not prove backup-operator coverage.