approval-engine/docs
tegwick d7a9fe53db Adopt Alpine as the sanctioned base; release candidate scans clean
Operator adopted Alpine/musl as the base and trivy as the scanner.
Containerfile.alpine is promoted to Containerfile and the Debian slim variant
is retired rather than kept as an option -- it shipped three perl-base
CRITICALs with no upstream fix, in a package this service never invokes.

Promoting Alpine left 7 HIGH and 1 MEDIUM, all libuuid 2.42.1-r0 as shipped by
the pinned Alpine 3.24.1, and all with fixes in 2.42.3. The runtime stage now
requires libuuid>=2.42.3-r1. That is a version floor, not a floating upgrade:
the base stays digest-pinned and reproducible, and a vulnerable libuuid fails
the build instead of shipping.

The candidate scans 0 CRITICAL / 0 HIGH / 0 MEDIUM / 0 LOW. Verified on that
exact artifact: non-root uid 10001, pip absent, schema v3, tenant default
tenant:platform, fresh-store migrate and verify clean, restart persistence via
re-verify on the same volume, both production fail-closed refusals, 111 tests
on musl, kubectl dry-run passing.

The gate is now reproducible instead of a one-off. make image-scan fails on any
CRITICAL or HIGH, and make image-release runs build then scan then push, so a
failing scan blocks the push by construction rather than by whoever remembers
to look.

Not released. docker push was attempted and refused by this session's sandbox
as an outward-facing publish, and was not worked around. No release digest
exists, so the manifest deliberately keeps REPLACE_WITH_RELEASE_DIGEST -- it
must be pinned to the registry manifest digest, never the tag and never the
local image id. T03 stays wait on that push plus the still-unmaterialized
KeyCape registrations and audit sender credential.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PM5HnEAhokxdfcPqBNpT7D

Assistant: claude-code
Assistant-Model: opus
Assistant-Process: 715850@bnt-lap001
Assistant-Session: eb557e93-7cb1-45d0-9e57-7d15b3edc60e
2026-09-06 23:01:41 +02:00
..
approval-claim.md Name the execute-time digest target; record the tenant collision 2026-09-06 20:35:59 +02:00
approval-consumption.md Record GH-DEC-2026-005; strike the spent G3 revisit trigger 2026-09-06 01:36:03 +02:00
caller-authentication.md Harden the PEP harness and KeyCape registration request 2026-09-02 15:46:06 +02:00
emission-cadence.md Implement approval engine production readiness 2026-09-02 00:52:04 +02:00
flex-auth-handoff.md Finish approval engine spine 2026-09-01 23:45:48 +02:00
gate-house-decision-request-claim-envelope.md chore(consistency): record decision id for GH-DEC-2026-005 2026-09-06 08:05:00 +02:00
image-scan-2026-09-06.md Adopt Alpine as the sanctioned base; release candidate scans clean 2026-09-06 23:01:41 +02:00
keycape-service-registrations.md Set the approval store tenant to exact tenant:platform 2026-09-06 22:33:50 +02:00
outbox-contract.md Carry threshold evidence on issuance and use events 2026-09-06 08:10:21 +02:00
pep-integration.md Harden the PEP harness and KeyCape registration request 2026-09-02 15:46:06 +02:00
storage-operations.md Implement GH-DEC-2026-008: declared PDP-path intent, enforced at issue 2026-09-06 14:51:23 +02:00