release: implement site registry v0.4 trust pipeline

This commit is contained in:
Nic Weyand 2026-09-13 12:22:05 -04:00
commit e26efc19fa
Signed by: nicweyand
SSH key fingerprint: SHA256:2te+ycJIQON/Wo/dH6+ZkFSQ4HnHWpetV2azx9E65dQ
67 changed files with 10698 additions and 640 deletions

View file

@ -14,8 +14,11 @@ affected generation. Use inert or local fixtures where possible.
Publishers should append a revocation for a suspected malicious destination,
build and inspect a replacement generation with the full review history, sign it
with a trusted key and deliver its new pin to consumers. Consumers must refresh
their verified registry and any derived routing catalogue. Merely appending a
local revocation does not notify running applications or invalidate their caches.
their verified registry and any derived routing catalogue. A seven-day emergency
feed can add blocks to an older compatible generation, but only the exact full
generation can clear one after the consumer recomputes the signed superseding
quorum. Merely appending a local revocation does not notify running applications
or invalidate their caches.
For signer compromise, remove that signer from consumer trust files through an
independent authenticated channel, investigate affected releases and rotate the