ADR 0010: Release Assurance Evidence Pipeline
Status
Accepted
This status accepts the architectural decision. It does not mean the complete pipeline is implemented; the implementation status below remains partial.
Date
2026-06-08
Context
The SDK needs release evidence that is machine-readable and fail-closed. Manual claims like "tests passed" are insufficient for conformance, supply-chain assurance, and auditability.
Decision
opc-evidence defines the SDK-owned data model and policy engine for the RFC
006 release-assurance pipeline.
It provides:
- Source extraction for RFC 006 tags such as
@spec,@req,@conformance,@gap,@security,@performance, and@test. - Deterministic CycloneDX SBOM generation from local Cargo manifests and lock data.
- VEX policy result and record validation.
- SLSA/in-toto-style provenance tied to commit, builder, input materials, output digests, and dirty/clean worktree state.
- Bundle assembly and verification with canonical manifest signing bytes.
- Signer/verifier traits and deterministic in-process test signing.
- Performance baseline schema with redaction-safe environment metadata and regression status.
- PR/release gate policy that fails closed on missing evidence, missing signatures, tampering, mismatched commits, dirty release provenance, malformed JSON, or unsafe evidence content.
Implementation status
The library primitives are implemented and tested. Signing inputs are
deterministic and domain-separated, signer/verifier identities are bound to the
manifest, manifest paths and digests fail closed, and GateEvaluator requires
separately supplied artifacts to exactly match their signed bundle values. The
signed manifest additionally binds the canonical record, gap, and waiver inputs
that drive the gate, and commit identities are cross-checked without disclosure.
Repository workflows still do not produce and enforce the complete RFC 006
artifact set or invoke the release policy evaluator with a production external
signer/verifier. Consequently, this ADR's end-to-end pipeline decision remains
only partially implemented.
Consequences
Release pipelines must treat evidence artifacts as required inputs, not as optional reports.
Real Sigstore/Cosign keyless signing remains an external signer adapter boundary. The SDK owns the signing/verifier interface and test verifier, not a hard dependency on one hosted signing provider.
Evidence
crates/opc-evidence/src/extract.rscrates/opc-evidence/src/sbom.rscrates/opc-evidence/src/vex.rscrates/opc-evidence/src/provenance.rscrates/opc-evidence/src/bundle.rscrates/opc-evidence/src/performance.rscrates/opc-evidence/src/policy.rscrates/opc-evidence/tests/evidence_bundle.rscrates/opc-evidence/tests/evidence_policy.rscrates/opc-evidence/tests/evidence_sbom_vex.rscrates/opc-evidence/tests/evidence_provenance.rs