Relationships
↔ sibling #2814#2815 build-attestation rejects every run: evaluated workflows now carry sensitiveFormat, which the provenance check treats as an uncommitted field
Opened by hammz · 9/30/2026· Shipped 9/30/2026
Summary
deno run build-attestation refuses every verify-build run made with a binary that includes swamp-club#2171 (518cbcbf), so no attestation can be generated for any branch, even when all verification steps pass.
verify-build run afd7dfe2-... did not execute verification/workflow-verify-build.yaml as it stands at a062af74...:
sensitiveFormat is in the evaluated workflow but not the committed definitionCause
swamp-club#2171 added a root-level sensitiveFormat: 1 marker (SENSITIVE_FORMAT_VERSION) to every persisted evaluated workflow (src/infrastructure/persistence/yaml_evaluated_workflow_repository.ts). checkWorkflowProvenance in scripts/build_attestation.ts compares the committed workflow YAML against .swamp/workflows-evaluated/runs//evaluated-workflow.yaml and accepts evaluated-only keys only when isEmptyDefault holds (empty, zero, false). sensitiveFormat is 1, so it is reported as a provenance mismatch. writtenReferences (also added by #2171) will trip the same check whenever a run records one.
Observed with swamp 20260930.143206.0-sha.fdd49f4d (origin/main) while verifying swamp-club#2814; all three verification workflows passed.
Fix direction
Strip the persistence-only metadata keys (sensitiveFormat, writtenReferences) from the evaluated document before the provenance comparison in scripts/build_attestation.ts, with a unit test that an evaluated workflow carrying them still matches its committed definition.
Shipped
Click a lifecycle step above to view its details.