Repository navigation
Add Parmana as a TRACE external evidence source - #294
Open
pavancharak wants to merge 1 commit into
Open
pavancharak wants to merge 1 commit into
pavancharak wants to merge 1 commit into
Conversation
pavancharak
requested review from
a team,
carloshvp and
imran-siddique
as code owners
October 10, 2026 19:24
Author
|
The server image with SLSA provenance is published: ghcr.io/pavancharak/parmana-api@sha256:f82c0076ebff847c5ae0afb5f9e3728e49c9dd819f8e52ba0d8659a960753865 (release server-v1.0.0, built at f95f786e). slsa-verifier verify-image ghcr.io/pavancharak/parmana-api@sha256:f82c0076ebff847c5ae0afb5f9e3728e49c9dd819f8e52ba0d8659a960753865 --source-uri github.com/pavancharak/parmana --source-tag server-v1.0.0 returns PASSED, builder generator_container_slsa3.yml@v2.1.0. f95f786e is the fixtures’ commit ac22a7ed plus only the commit that records the evaluation report and fixtures, so the image runs the same code that produced the fixtures. The hosted API is built by Vercel and carries no provenance. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Parmana as a TRACE external evidence source
Follows #286. Adds
integrations/parmana-server/: Parmana's signed authorization decisions mapped to TRACEreferences, with an offline checker and the fixtures from one evaluation run.Per your answers on #286 (trace-spec at
db95328):Role:
external-evidence-source, no conformance level. No TRACE Trust Record is issued, so no placeholdersubject,model,data_classorbuild_provenance.Signing: Parmana keeps its own canonical form and signatures. A runtime's Trust Record points at them:
authorized-intentto the Execution Trust Record or Refusal Record, andapproval-outcometo the signed approval (retained inside the Trust Record, at#/transaction/signals/approvalArtifact).Unit: one Parmana record per decision, refusals included.
Mocks: nothing is referenced as
observed-effect. The mock label stays infixtures/report.json, the README and a test.Re-pinned: the fixtures are one unedited run at pavancharak/parmana commit
ac22a7ed594b4a527504ce43841595c1a62f3046. That commit includes the Refusal Record policy content hash (all three records carry it) and the release workflow that publishes the server image with SLSA provenance.Reproduction
18 tests check:
every signature, with Parmana's public key only;
that a changed amount, outcome or approval limit fails;
that the approval is the one the Trust Record was signed over;
that all three decisions name one policy content hash;
that
references.jsonis exactly what the records produce and validates asagentrust_trace.Reference(0.11.0).To regenerate the fixtures from Parmana itself:
npm run evaluate:agentrust-refundat that commit (no network, keys or accounts).Licence
I, Pavan Dev Singh Charak, for Parmana Systems Private Limited, the copyright holder, license everything in
integrations/parmana-server/under the Apache License 2.0: the code, the README and the fixtures, which are records generated by Parmana in that run. TheparmanaPython SDK it depends on is Apache-2.0 on PyPI.Not claimed:
Any downstream effect: the connector in the run is a mock.
That the two caller-declared facts were checked: they can only refuse.
That the policy was approved through governance in the run: the governance anchor reads
NO_APPROVAL_RECORD.The README says the same.