Task — engineering-spec@1

"Payload supply-chain: pin Actions, emit SBOM, checksum posture"

doneTASK-IMP-043
module improvement · class product · priority p1 · created 2026-07-08 · shipped null
depends on none · blocks none

TASK-IMP-043: Payload supply-chain (pin, SBOM, checksum posture)

Summary

Pin official actions/* in suite-gate, payload-gate, and release.yml to full SHAs; emit CycloneDX SBOM for payload release; document SHA256SUMS integrity and deferred cosign.

Problem

Payload workflows pin Actions by mutable major tags. Releases publish SHA256SUMS but no SBOM. Full cosign-for-GHCR is platform-heavy for 1.x payload consumers.

Proposed Solution

SHA-pin official actions; emit-payload-sbom.sh (hermetic CycloneDX); upload SBOM from release.yml; document posture.

Alternatives Considered

Success Metrics

Scope

In scope: Action SHA pins, SBOM script, release upload, docs, tests.

Out of scope / Non-Goals

Dependencies

Adjacent to TASK-IMP-069.

AI Authorship Disclosure

1. Description (normative)

2. Acceptance criteria

3. Edge cases

Audit

§1 — Verdict summary

R25 reframed to payload pin + SBOM + checksum posture.

§2 — Findings

ISS-001 — Scope honesty (RESOLVED)

1.x payload scope recorded.

§3 — Resolution

Score = 9/10. Verdict PASS.