Skip to content

Add signed evidence bundle file attestation - #5

Merged
cybertechsoft merged 4 commits into
mainfrom
fix/evidence-bundle-integrity
Sep 20, 2026
Merged

cybertechsoft merged 4 commits into
mainfrom
fix/evidence-bundle-integrity

Conversation

@cybertechsoft

Copy link
Copy Markdown
Owner

Adds signed SHA-256 file attestation to Evidence Bundle v2 so exported
human-readable and verification artifacts are cryptographically bound to
the bundle.

This change:

  • covers exported bundle files with SHA-256 digests
  • signs the canonical bundle attestation with the configured LoopGrid signer
  • rejects modified, missing, or unexpected attested files
  • preserves existing ledger and checkpoint semantics
  • keeps legacy unattested Evidence Bundle v2 exports verifiable with an
    explicit legacy_unattested status
  • adds regression tests for bundle-file tampering

Local validation completed:

  • 58 tests passed
  • clean bundle verification passed
  • tampered report.html correctly rejected
  • tamper verification returned exit code 2
  • Docker build passed
  • Docker /health passed
  • Docker /ready passed
  • Docker quickstart passed
  • Docker-generated evidence independently verified

@cybertechsoft
cybertechsoft merged commit cbf9dbb into main Sep 20, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant