Skip to content

provenance source-fetch: no rung for the publisher's own source repository #4579

Description

@kyle-sexton

Problem

skills/audit/reference/source-fetch.md "The rungs" lists three routes: (1) the page's raw-markdown channel, (2) the page degraded through a summarizer or rendered HTML, (3) a verbatim third-party mirror with a freshness check. It has no rung for the publisher's own source repository, meaning the file the published page is built from. That route is common when a site's .md channel 404s.

A run has to guess whether such a read is rung 1 or 2 (first-party, no freshness check) or rung 3 (needs corroboration), and what to record in source.route.

Evidence

melodic-software/.github#153, provenance step: https://www.contributor-covenant.org/version/2/1/code_of_conduct.md returned 404. The run read raw.githubusercontent.com/EthicalSource/contributor_covenant/release/content/version/2/1/code_of_conduct.md instead. No harm this time: the version is frozen and the file was cleared.

Fix

Add a rung, or a note under rung 1, for the publisher's source repository. State the identity check it needs (for example, the branch that the site deploys from) and the source.route value to record.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs-triageNot yet classified. Floor until a type and one priority tier are set.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions