Skip to content

chore: sync core lib and CLAUDE.md from agent-core#24

Merged
avifenesh merged 1 commit into
mainfrom
chore/sync-core-perf-20260426-175520
Apr 26, 2026
Merged

chore: sync core lib and CLAUDE.md from agent-core#24
avifenesh merged 1 commit into
mainfrom
chore/sync-core-perf-20260426-175520

Conversation

@avifenesh
Copy link
Copy Markdown
Contributor

@avifenesh avifenesh commented Apr 26, 2026

Automated sync of lib/ and CLAUDE.md from agent-core.


Note

Medium Risk
Adds an additional provenance-verification gate (gh attestation verify) to the binary download/install path, which can cause new install failures when gh is present but verification fails or when attestation is required in CI.

Overview
Strengthens the binary download/install flow by adding an optional (or CI-required) SLSA build provenance verification step via gh attestation verify, in addition to the existing .sha256 sidecar check.

Introduces verifySlsaAttestation/isGhAvailable helpers and new downloadBinary/ensureBinary/ensureBinarySync options (skipAttestation, requireAttestation, injectable ghRunner/ghProbe), including forwarding requireAttestation through the sync child-process path and failing installs on attestation verification errors.

Reviewed by Cursor Bugbot for commit 6c0a59b. Configure here.

@gemini-code-assist
Copy link
Copy Markdown

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@avifenesh avifenesh merged commit fd62494 into main Apr 26, 2026
5 checks passed
@avifenesh avifenesh deleted the chore/sync-core-perf-20260426-175520 branch April 26, 2026 17:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant