CI / release workflows
PUBLIC REPOSITORY
RELEASE GOVERNANCE
The public protocol repository has an active default-branch ruleset and a published pub.2 release. Public Site 80 reports the ruleset exactly: pull-request workflow, review-thread resolution, deletion protection and non-fast-forward protection. The current ruleset does not contain a required-status-check rule, so Finality does not claim that it does.
Repository control
The active Protect main ruleset applies to the default branch. These are governance controls, not independent protocol assurance.
Workflow evidence
CI, CodeQL, Scorecard, fuzzing and release-provenance workflows may produce integrity evidence. Their existence or historical success does not make them required by the current branch ruleset and never creates E4/E5 independence.
PUBLIC REPOSITORY
PRESENT
PRESENT
PRESENT
NOT PRESENT
Publication rule
The public repository exposes external-proof-v2.0.0-draft.1-pub.2 and release assets including a Sigstore bundle. Public Site 80 preserves rather than rewrites that frozen protocol-publication identity.
FRP-2.0.0-draft.1
FSK-1.0.0
external-proof-v2.0.0-draft.1-pub.2
PUBLIC RELEASE ASSET
ZERO