Watch
1
0
Fork
You've already forked RedFlag
0
RedFlag/RAF/security
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Fimeg 320ad46e00 feat(helper): accept dormant mutation envelopes
Cut 2 adds a verify-envelope path beside the closure-token executor. The helper parses an envelope, binds it to the independently provisioned agent identity, validates time and lifetime bounds, selects the trusted key, verifies the signed contract, checks backend payload shape, and then refuses with backend_not_migrated.

Every path emits an unsigned MutationReceipt. No backend executes, no replay slot is consumed, and no artifact-custody claim is made until the first existing backend migrates.
2026-08-26 18:39:41 -04:00
..
01-trust-boundaries.md v0.2.9.3: device classification + ARM support — Pixel 3 lands 2026-07-06 18:21:23 -04:00
02-authentication-stack.md raf: sync docs to code + relative cross-reference links 2026-06-15 09:39:34 -04:00
03-refresh-tokens.md raf: sync docs to code + relative cross-reference links 2026-06-15 09:39:34 -04:00
04-machine-binding.md RAF: full docs pass — components, flows, security, scanners, reference, testing, verification, overview 2026-06-11 11:32:21 -04:00
05-supply-chain-gate.md feat(helper): accept dormant mutation envelopes 2026-08-26 18:39:41 -04:00
06-standalone-authority.md docs: bind the supply-chain claims to the helper 2026-08-25 08:26:05 -04:00