Skip to main content
← Back to list
01Issue
FeatureOpenSwamp CLITeam
AssigneesNone

Relationships

#1595 Explore: reconcile quality rubric's dormant provenance factor

Opened by webframp · 8/11/2026

Problem statement

The extension quality rubric (references/extension/references/quality/rubric.md) already documents a provenance factor — "Sigstore-signed bundle verified by the server" — gated off via a flag (PROVENANCE_IN_RUBRIC = false) with a note that CLI-side signing support hasn't shipped. This is a small housekeeping loose end: the doc names a feature that doesn't exist in code, and nothing currently tracks reconciling that.

This is one candidate idea, not a proposed requirement

This is the lowest-stakes of a set of related exploratory issues (#1592, #1593, #1594) about extension supply-chain provenance. It's really a doc/config follow-up, not a design question — filed mainly so it doesn't get silently forgotten if the other three are ever pursued, and could reasonably be closed as "tracked in #1592-#1594" rather than actioned independently.

Once publish-time signing and pull-time verification exist, flip PROVENANCE_IN_RUBRIC on and update the rubric doc to describe actual behavior instead of an aspirational one.

Alternatives considered

  • Remove the dormant rubric entry entirely rather than tracking it, if the team decides not to pursue #1592-#1594. Either resolution is fine; the point of filing is just to make sure someone decides, rather than the doc silently drifting from reality.
02Bog Flow
OPENTRIAGEDIN PROGRESSSHIPPED

Open

8/11/2026, 3:25:54 AM

No activity in this phase yet.

03Sludge Pulse

Sign in to post a ripple.