Skip to content

[AI-generated] Make WASM and CI inputs verifiable and reproducible #10

Description

@timonwong

AI-generated issue: drafted and opened by AI Agent from the commit 7d7621314b73dec06255434e4cacce249de3d181.

Problem

The build claims pinned and reproducible inputs, but several supply-chain inputs are mutable or lack integrity verification:

  • buildtools/wasm/Dockerfile:1 uses mutable debian:13-slim.
  • buildtools/wasm/Dockerfile:6-9 installs unversioned apt packages.
  • buildtools/wasm/Dockerfile:13-17 downloads ghc-wasm-meta without a checksum.
  • buildtools/wasm/build.sh:21-22 downloads the pre-seeded fgl tarball without a checksum.
  • scripts/fetch-native-shellcheck.sh:27-36 downloads the native parity binary without checksum or signature verification.
  • .github/workflows/ci.yml:33-40 and release.yml:43-50 explicitly disable BuildKit provenance.

Impact

A changed upstream image, package, archive, or release asset can silently alter CI behavior or the published WASM artifact. npm provenance does not attest the separately built WASM asset.

Acceptance criteria

  • Pin the base image by digest.
  • Pin or snapshot apt inputs where practical.
  • Verify ghc-wasm-meta, fgl, and native ShellCheck downloads with checksums or signatures.
  • Enable verifiable build provenance and SBOM for the WASM build and publish it separately from the npm tarball.
  • Add CI checks proving the recorded build metadata corresponds to the verified inputs.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    ai-generatedIssue drafted and opened by an AI AgentbugSomething isn't workingdependenciesPull requests that update a dependency filegithub_actionsPull requests that update GitHub Actions code

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions