Frozen-composition publishing pipeline for Arcaven-curated sideshow packs.
Produces signed, versioned tarballs of multi-source content packs (BMAD, VSDD, etc.) suitable for consumption by sideshow without executing untrusted JavaScript on user machines.
Status: MVP. First release published: bmad-v6.3.0
(2026-04-26, signed via cosign keyless OIDC). vsdd-factory + dark-factory
pending (aae-orc-amet).
Visibility: public. The build script + workflow are not source
materials we need to restrict. Release-asset tarballs contain upstream
content under upstream licenses (bmad-method is MIT). When a future
pack ships content that genuinely cannot be redistributed, that
specific pack moves to a private mirror or alternate distribution
channel; today's bmad arc has no such constraint. Visibility was
flipped from private during u84w because GitHub's free plan blocks
actions/attest-build-provenance on private repos.
See docs/release-url-format.md for the
canonical contract: tag pattern, asset filenames, verification recipe,
identity binding. Sideshow's client-side fetch + verify
(aae-orc-wk92) consumes that contract.
registry/<pack>-pack-support.yaml records, per pack: the validated version
brackets (with evidence), the pipeline assumptions that define
"supported," and the known upstream wrinkles (version-bracketed, with
the adaptation each one required). scripts/check-support.sh gates
every build on it: versions outside all validated brackets refuse to
build unless ALLOW_UNSUPPORTED=1 (workflow input
allow_unsupported), and the refusal message points at
registry/pack-support-revalidation-runbook.md
— executable instructions for an LLM or human to re-validate a new
version and extend the bracket with evidence. The register tracks
upstream packaging wrinkles; published-artifact defects are the
separate known-defects registry (aae-orc-ztg5).
External modules are pinned to the newest tag published on or before the
upstream release date, so a pack never picks up a module release that came
after it. scripts/pin-lag.sh <install.meta.yaml> lists, per module, the
upstream tags newer than the pin. It reports and exits 0; it does not gate.
For each pack version, the pipeline emits:
<pack>-<version>-arcaven.tar.gz— the pack tree in sideshow's user-install layout (pack content at root,.claude/as sibling for tool bindings).install.meta.yaml— provenance manifest: upstream git sha, npm tarball sha, per-module versions + sources, install invocation, tarball sha256.file-manifest.csv— per-file sha256 + size.install.meta.yaml.sig+install.meta.yaml.bundle— cosign signature + Sigstore Rekor transparency log bundle.<pack>-<version>-arcaven.tar.gz.sig+.bundle— same for the tarball itself.- Provenance attestation via
cosign attest-blob— SLSA/in-toto attestation linking tarball sha to upstream source shas.
Signed artifacts are published as GitHub Release assets on this repo
(private). sideshow's install.source contract (aae-orc-h07h) will
reference the release URLs. A stripped-down public mirror will be
added later via aae-orc-<TBD>.
Requires: node (≥ 18), npx, yq, bash. cosign optional (signing
is skipped locally without it).
# Default: bmad 6.3.0 with all modules + claude-code bindings
BMAD_VERSION=6.3.0 scripts/build-bmad.sh
ls artifacts/Produces artifacts in ./artifacts/. Not signed unless COSIGN=1 and
you have cosign configured.
Triggered by:
- Manual dispatch with inputs: pack name + version.
- Push of a version tag matching
<pack>-v<semver>.
See .github/workflows/build-pack.yml. Signing uses cosign keyless
OIDC via GitHub Actions — no keys to rotate.
aae-orc-ibil— this pipeline (the one you're reading).aae-orc-entu— source-material provenance chain (consumed by thecosign attest-blobstep).aae-orc-mezl— pluggable source backends (consumers install via GitHub Releases backend; future: CDN, apt, plugin marketplace).aae-orc-h07h—pack.yaml install:contract that references the signed artifacts from this pipeline.aae-orc-10vq— overlay artifact spec; overlays also publish via this pipeline.aae-orc-7dri— install parity test consumesfile-manifest.csvas the golden reference.aae-orc-amet— VSDD ecosystem packs (vsdd, dark-factory, vsdd-factory) to add next.
See also _kos/findings/finding-025-* and finding-027-* in the orc
repo for the probe evidence this pipeline is built from.