Repository navigation
feat(build): pin Gradle distribution with SHA256 checksum - #603
Merged
Merged
Conversation
…-hq#470) Add distributionSha256Sum to gradle-wrapper.properties to cryptographically verify the Gradle distribution matches the intended version. This satisfies REQUIREMENT-BUILD-INPUT-INTEGRITY-1 and allows the Gradle grant to rest on code rather than prose.
…#470) Verifies that Gradle wrapper configuration maintains: - Download host pinning to services.gradle.org (prevents supply chain redirection) - SHA256 checksum presence and validity (ensures distribution integrity) Fails closed on any missing or invalid configuration.
📊 Metrics Regression Report✅ All metrics within tolerance Summary
Detailsai-expense-approval.bpmn.transitrix.yaml
feature-release.bpmn.transitrix.yaml
large-cyclic-workflow.bpmn.transitrix.yaml
order-fulfillment.bpmn.transitrix.yaml
parallel-tracks.bpmn.transitrix.yaml
simple-approval.bpmn.transitrix.yaml
simple-linear.bpmn.transitrix.yaml
small-dense-approval.bpmn.transitrix.yaml
xlarge-stress-test.bpmn.transitrix.yaml
|
transitrix
added a commit
that referenced
this pull request
Aug 31, 2026
Fold accumulated changelog fragments into CHANGELOG.md, restore two entries dropped by a bad merge in #603, and bump versions: extension/root 3.5.0 -> 3.6.0, @transitrix/diagrams 1.11.0 -> 1.12.0, @transitrix/cli 2.7.0 -> 2.8.0. Signed-off-by: transitrix <automation@transitrix.com>
vkgeorgia
pushed a commit
that referenced
this pull request
Aug 31, 2026
Restores findCanonRootPath and findModelRootPath that were accidentally deleted in PR #603. The resolver searches for transitrix.yaml to locate the model root, then resolves canon/ from there (normative layout), with fallback to legacy basename-canon walk. Includes the two unit tests that verify both normative and legacy layouts resolve correctly. Deleting the tests without deleting the resolver would allow a future merge to drop the walker again silently. Fixes the regression in 3.6.0 where the fix was described in release notes but missing from the published VSIX. Fixes transitrix-hq#485. Co-authored-by: Claude Haiku 4.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds
distributionSha256Sumto gradle-wrapper.properties to cryptographically verify the Gradle distribution.Adds CI workflow that verifies:
services.gradle.org(prevents supply-chain redirection)Verification
acd53f1edaf02f1a8ff99879f8a34b302661a057d9b063ae9e35b552f804d20adistributionUrlanddistributionSha256Sum