Commit graph

2 commits

Author SHA1 Message Date
Austin Schaefer
8443ecea69 Narrow scope: personal middle ground, not a security framework
Adds an explicit Scope/Non-Goals section (curated personal package list,
not adversarial-config or compromised-vendor-pipeline defense) and a
post-build version sanity check as its own pipeline stage, distinct from
the trust tiers — a correctness gate (does the build report the version
we expected), not a security control. Trims the next-steps list to match.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A2FEut5tVMNjeVjqhgVZbr
2026-09-11 09:10:06 +02:00
Austin Schaefer
0fa994f60a Add initial design spec for declarative package-update watcher
Captures the verification trust-tier model (pinned-key signatures down to
trust-me-bro install scripts) and the daemon architecture discussed: check
-> fetch -> tier-aware verify -> PKGBUILD gen -> local repo publish, with
weak-tier changes routed to human review instead of auto-publish.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01A2FEut5tVMNjeVjqhgVZbr
2026-09-11 09:01:30 +02:00