Independent security review and deployments will determine whether ProofCore’s GitHub Action provides reliable zero-storage release notarization through GitHub OIDC without introducing a separate signing-service trust boundary.
state: expiredheat: lowuncertainty: highknownscott: lowsoftware-supply-chain release-provenance github-oidcProofCore Protocol
What is this?
ProofCore Protocol presents ProofCore as an open-source GitHub Action for notarizing software releases using GitHub OIDC, with the claimed benefits of zero stored credentials and no separate signing-service trust boundary. The supplied GitHub and security snippets support the general mechanism—GitHub Actions can use OIDC to obtain short-lived tokens instead of static secrets—but they do not independently document ProofCore’s architecture, deployments, audit results, or reliability. Whether its notarization is genuinely zero-storage and avoids merely relocating trust therefore remains unestablished by the provided evidence.
Why it matters to Scott
Scott already holds the governing position in “Agent Provenance Stack” and “Mechanically Different Verifiers”: release provenance must bind identity, artefact and execution, while security claims require genuinely independent checks. ProofCore is currently only an unverified implementation candidate, although its GitHub OIDC trust boundary intersects the radar’s existing “GitHub Actions OIDC audience gap” case; without architecture, audits or deployments, it does not yet extend or challenge Scott’s position.
ip:framework.agent-provenance-stackip:concept.mechanically-different-verifiersip:concept.provenance-is-not-trustdev:concept.validated-release-preview-boundaryradar:github-actions-oidc-audience-gapradar:concept.github-actionsradar:concept.software-supply-chain
queries asked of Scott's wikis
- keyless signing and release provenance
- GitHub Actions OIDC trust boundaries
- software supply-chain notarization
- CI/CD credential isolation and zero-storage security
- independent verification of security tooling
- artifact signing versus external transparency logs
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-27T09:36:33Z
No independent review, deployment, architecture disclosure, or security finding emerged within the observation horizon. The implementation remains unvalidated, but without a live confirming path the episode has faded rather than advanced.
2026-08-25T08:27:39Z
The re-evaluation adds no substantive evidence: ProofCore remains an unvalidated implementation whose trust-boundary and zero-storage claims await independent review or real deployments. Unchanged engagement provides no basis for promotion or renewed attention.
2026-08-25T08:26:29Z
grounded: known/low — Scott already holds the governing position in “Agent Provenance Stack” and “Mechanically Different Verifiers”: release provenance must bind identity, artefact a
2026-08-25T08:23:59Z
case created — The first-party repository is a concrete security artifact, but its security properties and practical adoption remain unvalidated.
Decision trace
- 08-27 19:36expireNo independent review, deployment, architecture disclosure, or security finding emerged within the observation horizon. The implementation remains unvalidated, but without a live confirming path the e
- 08-27 19:36alert_silentThe staleness trigger carries no substantive new evidence, and repetition of the original release claim does not warrant Scott’s attention.
- 08-27 19:36alert_routeThe staleness trigger carries no substantive new evidence, and repetition of the original release claim does not warrant Scott’s attention.
- 08-25 18:27repriceThe re-evaluation adds no substantive evidence: ProofCore remains an unvalidated implementation whose trust-boundary and zero-storage claims await independent review or real deployments. Unchanged eng
- 08-25 18:27alert_silentNo new architecture, audit, deployment, or security finding has appeared, so the delta does not merit interrupting Scott or the next briefing.
- 08-25 18:27alert_routeNo new architecture, audit, deployment, or security finding has appeared, so the delta does not merit interrupting Scott or the next briefing.
- 08-25 18:26alert_silentThe only established delta is that ProofCore has published an open-source GitHub Action claiming zero-storage release notarization via GitHub OIDC. No architecture, audit, deployment evidence, release
- 08-25 18:26alert_routeThe only established delta is that ProofCore has published an open-source GitHub Action claiming zero-storage release notarization via GitHub OIDC. No architecture, audit, deployment evidence, release
- 08-25 18:26groundScott already holds the governing position in “Agent Provenance Stack” and “Mechanically Different Verifiers”: release provenance must bind identity, artefact and execution, while security claims requ
- 08-25 18:23createThe first-party repository is a concrete security artifact, but its security properties and practical adoption remain unvalidated.