Skip to content
This repository was archived by the owner on Oct 2, 2026. It is now read-only.

chore(deps): update weight-custody-manifest requirement from >=0.28.2 to >=0.28.4 - #130

Merged
imran-siddique merged 1 commit into
mainfrom
dependabot/pip/weight-custody-manifest-gte-0.28.4
Sep 28, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
dependabot/pip/weight-custody-manifest-gte-0.28.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Updates the requirements on weight-custody-manifest to permit the latest version.

Release notes

Sourced from weight-custody-manifest's releases.

WCM 0.28.4

What's Changed

Full Changelog: agentrust-io/weight-custody-manifest@v0.28.3...v0.28.4

Changelog

Sourced from weight-custody-manifest's changelog.

0.28.4 - 2026-09-24

The v0.28.3 tag points at a commit before the version bump and was never published; 0.28.4 is the first release carrying this section.

Security (GHSA-j665-99rh-w85h). Key release now requires the GPU report to state confidential-compute mode on. Before this, no gate read cc_mode, so a CC-capable GPU with the mode off passed all 13 checks and received the key. A missing or non-boolean cc_mode is now unknown, not on, and is denied (WCM-L2-0018). required_gpu_measurement.require_cc_mode: false waives the check; the field is optional, so existing signed manifests keep their pre-image. SPEC 3.2 gains the matching failure row. Reported by Zoheb Shaik.

Package the composed research harness with a standalone launcher, immutable source revisions and evaluated dependency versions. CI repeats all 36 cases from the extracted ZIP in a fresh environment. This remains a source-based software evaluation while the required protocol package releases are pending.

Reject overflowing host-supplied chunk-size sums in the restricted firmware's QemuKernelFetchBlob before allocation or payload reads. Compile the actual upstream and patched C for boundary, failure and mutation controls. This hardens the provisional source profile; firmware and SNP hardware acceptance stay open.

Add a read-only native-SNP host preflight and partner execution packet. Missing or unavailable prerequisites require host review; successful observations never claim hardware acceptance. No VM launch or host configuration change is performed.

Predict the actual built firmware/kernel/broker initramfs in CI, repeat the baseline and require seven launch-input substitutions to change the digest. Retain exact artifact identities and candidate launch parameters. This is software prediction evidence; matching hardware and firmware approval remain open.

Record real GCP native-SNP report controls and owner-side verification. A fresh report retains its launch measurement after an application probe file changes. The native provisioning collector binds supplied bytes; protected broker identity, custom firmware and key custody remain unvalidated by this run.

Add a live Azure SNP/vTPM diagnostic with independently supplied roots and owner nonces. Real-hardware controls reject six evidence substitutions and reproduce the caller-supplied PCR23 digest limitation after a probe file changes. This does not validate the custom firmware or native-SNP broker provisioning.

Add an experimental restricted edk2 build profile: require the complete launch hash table, reject named and IGVM boot blobs, and stop before generic BDS boot options if the verified kernel fails or returns. Remove GRUB and shell payloads. Native C controls, repeated candidate builds and separately instrumented complete-image TCG controls run in Linux CI. Test firmware injects synthetic launch state and is explicitly unsuitable for custody. This is not production firmware approval or SNP hardware validation.

... (truncated)

Commits
  • 855c0a8 chore(release): 0.28.4 (#158)
  • 825b1e1 chore(release): 0.28.3 (#157)
  • 596ca42 fix(kbs): require GPU confidential-compute mode before key release (#156)
  • 34e471f docs(governance): record Custodian commercial-interest disclosure (#155)
  • 3fb62b0 Package composed research reproduction and verify it from a fresh environment...
  • 2810092 build(deps): bump actions/download-artifact from 4.3.0 to 8.0.1 (#152)
  • 723c005 fix(firmware): reject overflowing fw_cfg blob sizes (#153)
  • 77cb4cb docs: link AgenTrust LinkedIn community page
  • 46df83c docs: link AgenTrust LinkedIn community page
  • 9e6349b feat(conformance): a fifth binding kind, nonce-echo (#128) (#130)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Updates the requirements on [weight-custody-manifest](https://github.com/agentrust-io/weight-custody-manifest) to permit the latest version.
- [Release notes](https://github.com/agentrust-io/weight-custody-manifest/releases)
- [Changelog](https://github.com/agentrust-io/weight-custody-manifest/blob/main/CHANGELOG.md)
- [Commits](agentrust-io/weight-custody-manifest@v0.28.2...v0.28.4)

---
updated-dependencies:
- dependency-name: weight-custody-manifest
  dependency-version: 0.28.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026
@dependabot
dependabot Bot requested review from a team and carloshvp as code owners September 28, 2026 10:54
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python Pull requests that update python code labels Sep 28, 2026

@imran-siddique imran-siddique left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependency update, CI green.

@imran-siddique
imran-siddique merged commit 3d7ddb8 into main Sep 28, 2026
20 of 21 checks passed
@imran-siddique
imran-siddique deleted the dependabot/pip/weight-custody-manifest-gte-0.28.4 branch September 28, 2026 19:42
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

dependencies Pull requests that update a dependency file python Pull requests that update python code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant