2026-10-11 18:02 UTC

Independent security review and deployments will determine whether ProofCore’s GitHub Action provides reliable zero-storage release notarization through GitHub OIDC without introducing a separate signing-service trust boundary.

state: expiredheat: lowuncertainty: highknownscott: lowsoftware-supply-chain release-provenance github-oidcProofCore Protocol

What is this?

ProofCore Protocol presents ProofCore as an open-source GitHub Action for notarizing software releases using GitHub OIDC, with the claimed benefits of zero stored credentials and no separate signing-service trust boundary. The supplied GitHub and security snippets support the general mechanism—GitHub Actions can use OIDC to obtain short-lived tokens instead of static secrets—but they do not independently document ProofCore’s architecture, deployments, audit results, or reliability. Whether its notarization is genuinely zero-storage and avoids merely relocating trust therefore remains unestablished by the provided evidence.

Why it matters to Scott

Scott already holds the governing position in “Agent Provenance Stack” and “Mechanically Different Verifiers”: release provenance must bind identity, artefact and execution, while security claims require genuinely independent checks. ProofCore is currently only an unverified implementation candidate, although its GitHub OIDC trust boundary intersects the radar’s existing “GitHub Actions OIDC audience gap” case; without architecture, audits or deployments, it does not yet extend or challenge Scott’s position.
ip:framework.agent-provenance-stackip:concept.mechanically-different-verifiersip:concept.provenance-is-not-trustdev:concept.validated-release-preview-boundaryradar:github-actions-oidc-audience-gapradar:concept.github-actionsradar:concept.software-supply-chain
queries asked of Scott's wikis
  • keyless signing and release provenance
  • GitHub Actions OIDC trust boundaries
  • software supply-chain notarization
  • CI/CD credential isolation and zero-storage security
  • independent verification of security tooling
  • artifact signing versus external transparency logs

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnProofCore: Zero-storage release notarization for GitHub using OIDCproofcore_proto10
🟧 echo.github ⭐An open-source GitHub Action for zero-storage software-release notarization using GitHub OIDC.ProofCore Protocol——

Interpretation history

Decision trace