Skip to content

Bind pinned Apple receipts to verified source commits - #705

Open
PrzemyslawKlys wants to merge 1 commit into
mainfrom
feature/fix-apple-receipt-source-commit
Open

Bind pinned Apple receipts to verified source commits#705
PrzemyslawKlys wants to merge 1 commit into
mainfrom
feature/fix-apple-receipt-source-commit

Conversation

@PrzemyslawKlys

Copy link
Copy Markdown
Member

Pinned local Apple release operations now bind every generated plan and receipt to the exact verified consumer HEAD. Operators no longer need to repeat --apple-source-commit for routine commands such as Status.

The forwarding boundary also rejects empty, malformed, duplicate, or mismatched source values and normalizes the supported --apple-source-commit=<sha> form before invoking the CLI. Local capture-provenance arguments remain wrapper-only, and other Apple command families are unchanged.

This closes the gap where a successful Apple Status receipt could have no sourceCommit, making later pinned evidence checks reject it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant