AI-generated issue: drafted and opened by AI Agent from the commit 7d7621314b73dec06255434e4cacce249de3d181.
Problem
The build claims pinned and reproducible inputs, but several supply-chain inputs are mutable or lack integrity verification:
buildtools/wasm/Dockerfile:1 uses mutable debian:13-slim.
buildtools/wasm/Dockerfile:6-9 installs unversioned apt packages.
buildtools/wasm/Dockerfile:13-17 downloads ghc-wasm-meta without a checksum.
buildtools/wasm/build.sh:21-22 downloads the pre-seeded fgl tarball without a checksum.
scripts/fetch-native-shellcheck.sh:27-36 downloads the native parity binary without checksum or signature verification.
.github/workflows/ci.yml:33-40 and release.yml:43-50 explicitly disable BuildKit provenance.
Impact
A changed upstream image, package, archive, or release asset can silently alter CI behavior or the published WASM artifact. npm provenance does not attest the separately built WASM asset.
Acceptance criteria
- Pin the base image by digest.
- Pin or snapshot apt inputs where practical.
- Verify ghc-wasm-meta,
fgl, and native ShellCheck downloads with checksums or signatures.
- Enable verifiable build provenance and SBOM for the WASM build and publish it separately from the npm tarball.
- Add CI checks proving the recorded build metadata corresponds to the verified inputs.
AI-generated issue: drafted and opened by AI Agent from the commit
7d7621314b73dec06255434e4cacce249de3d181.Problem
The build claims pinned and reproducible inputs, but several supply-chain inputs are mutable or lack integrity verification:
buildtools/wasm/Dockerfile:1uses mutabledebian:13-slim.buildtools/wasm/Dockerfile:6-9installs unversioned apt packages.buildtools/wasm/Dockerfile:13-17downloads ghc-wasm-meta without a checksum.buildtools/wasm/build.sh:21-22downloads the pre-seededfgltarball without a checksum.scripts/fetch-native-shellcheck.sh:27-36downloads the native parity binary without checksum or signature verification..github/workflows/ci.yml:33-40andrelease.yml:43-50explicitly disable BuildKit provenance.Impact
A changed upstream image, package, archive, or release asset can silently alter CI behavior or the published WASM artifact. npm provenance does not attest the separately built WASM asset.
Acceptance criteria
fgl, and native ShellCheck downloads with checksums or signatures.