Skip to content

About

Frozen-composition publishing pipeline for Arcaven-curated sideshow packs (bmad, vsdd, etc.). Signed tarballs via cosign keyless OIDC + Sigstore Rekor.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

74 Commits

Folders and files

Repository files navigation

sideshow-packs

Frozen-composition publishing pipeline for Arcaven-curated sideshow packs.

Produces signed, versioned tarballs of multi-source content packs (BMAD, VSDD, etc.) suitable for consumption by sideshow without executing untrusted JavaScript on user machines.

Status: MVP. First release published: bmad-v6.3.0 (2026-04-26, signed via cosign keyless OIDC). vsdd-factory + dark-factory pending (aae-orc-amet).

Visibility: public. The build script + workflow are not source materials we need to restrict. Release-asset tarballs contain upstream content under upstream licenses (bmad-method is MIT). When a future pack ships content that genuinely cannot be redistributed, that specific pack moves to a private mirror or alternate distribution channel; today's bmad arc has no such constraint. Visibility was flipped from private during u84w because GitHub's free plan blocks actions/attest-build-provenance on private repos.

Release URL format

See docs/release-url-format.md for the canonical contract: tag pattern, asset filenames, verification recipe, identity binding. Sideshow's client-side fetch + verify (aae-orc-wk92) consumes that contract.

Packaging-support register

registry/<pack>-pack-support.yaml records, per pack: the validated version brackets (with evidence), the pipeline assumptions that define "supported," and the known upstream wrinkles (version-bracketed, with the adaptation each one required). scripts/check-support.sh gates every build on it: versions outside all validated brackets refuse to build unless ALLOW_UNSUPPORTED=1 (workflow input allow_unsupported), and the refusal message points at registry/pack-support-revalidation-runbook.md — executable instructions for an LLM or human to re-validate a new version and extend the bracket with evidence. The register tracks upstream packaging wrinkles; published-artifact defects are the separate known-defects registry (aae-orc-ztg5).

Pin lag

External modules are pinned to the newest tag published on or before the upstream release date, so a pack never picks up a module release that came after it. scripts/pin-lag.sh <install.meta.yaml> lists, per module, the upstream tags newer than the pin. It reports and exits 0; it does not gate.

What this produces

For each pack version, the pipeline emits:

  • <pack>-<version>-arcaven.tar.gz — the pack tree in sideshow's user-install layout (pack content at root, .claude/ as sibling for tool bindings).
  • install.meta.yaml — provenance manifest: upstream git sha, npm tarball sha, per-module versions + sources, install invocation, tarball sha256.
  • file-manifest.csv — per-file sha256 + size.
  • install.meta.yaml.sig + install.meta.yaml.bundle — cosign signature + Sigstore Rekor transparency log bundle.
  • <pack>-<version>-arcaven.tar.gz.sig + .bundle — same for the tarball itself.
  • Provenance attestation via cosign attest-blob — SLSA/in-toto attestation linking tarball sha to upstream source shas.

Distribution

Signed artifacts are published as GitHub Release assets on this repo (private). sideshow's install.source contract (aae-orc-h07h) will reference the release URLs. A stripped-down public mirror will be added later via aae-orc-<TBD>.

Local build

Requires: node (≥ 18), npx, yq, bash. cosign optional (signing is skipped locally without it).

# Default: bmad 6.3.0 with all modules + claude-code bindings
BMAD_VERSION=6.3.0 scripts/build-bmad.sh
ls artifacts/

Produces artifacts in ./artifacts/. Not signed unless COSIGN=1 and you have cosign configured.

CI build

Triggered by:

  • Manual dispatch with inputs: pack name + version.
  • Push of a version tag matching <pack>-v<semver>.

See .github/workflows/build-pack.yml. Signing uses cosign keyless OIDC via GitHub Actions — no keys to rotate.

Related orchestrator issues

  • aae-orc-ibil — this pipeline (the one you're reading).
  • aae-orc-entu — source-material provenance chain (consumed by the cosign attest-blob step).
  • aae-orc-mezl — pluggable source backends (consumers install via GitHub Releases backend; future: CDN, apt, plugin marketplace).
  • aae-orc-h07h — pack.yaml install: contract that references the signed artifacts from this pipeline.
  • aae-orc-10vq — overlay artifact spec; overlays also publish via this pipeline.
  • aae-orc-7dri — install parity test consumes file-manifest.csv as the golden reference.
  • aae-orc-amet — VSDD ecosystem packs (vsdd, dark-factory, vsdd-factory) to add next.

See also _kos/findings/finding-025-* and finding-027-* in the orc repo for the probe evidence this pipeline is built from.

About

Frozen-composition publishing pipeline for Arcaven-curated sideshow packs (bmad, vsdd, etc.). Signed tarballs via cosign keyless OIDC + Sigstore Rekor.

Topics

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages