Skip to content

[Feature] Module Trust Chain & CI Security #187

@djm81

Description

@djm81

Overview

Feature grouping for CI-driven module signing and manifest trust chain enforcement in specfact-cli-modules.

Mirrors specfact-cli#353 — Module Trust Chain & CI Security Feature — on the modules-repo side.

Problem

Module signing currently requires the private key locally, blocking non-interactive development (AI agents, Cursor, headless CI) on feature/dev branches. This feature moves signing to fully automated CI steps triggered by PR approval.

Scope

  • marketplace-06-ci-module-signing — CI-driven module signing on PR approval (#185)

Parent

Epic: #186 — Architecture (module security & CI)


Generated by OpenSpec hierarchy sync.

Metadata

Metadata

Assignees

No one assigned

    Labels

    FeatureFeature grouping of related User Storieschange-proposalProposal for a new changeenhancementNew feature or requestmarketplaceSpecfact Marketplace related topicopenspecopenspec change

    Projects

    Status

    Done

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions