ADRs tagged supply-chain¶
Auto-generated by scripts/docs/generate-adr-by-tag.sh. Edit ADR Tags: lines to update.
55 ADR(s) carry this tag.
| ID | Title |
|---|---|
| ADR-0010 | Sign release artifacts keyless via Sigstore |
| ADR-0027 | Non-conservative image pins with experimental toolchain flags |
| ADR-0038 | Purge upstream MATLAB MEX compiled binaries from tree |
| ADR-0039 | Pull forward runtime op-allowlist walk and model registry |
| ADR-0166 | MCP server release artifact channel — PyPI + GitHub release attachment + Sigstore (T7-2) |
| ADR-0211 | Tiny-model registry schema + Sigstore --tiny-model-verify |
| ADR-0263 | OSSF Scorecard policy and remediation cadence |
| ADR-0412 | Fork-local release-artefact mirror scaffold for u2netp.pth (Apache-2.0) |
| ADR-0603 | Ubuntu 26.04 (Resolute Raccoon) fallout fixes — CUDA 13.2, Python 3.14, apt renames |
| ADR-0604 | Add Renovate customManager for ROCm apt-repo tracking |
| ADR-0605 | Renovate customManagers for all dev/Containerfile pinned dependencies |
| ADR-0875 | GitHub Actions hardening audit (2026-05-30) |
| ADR-0902 | Signing and attestation audit — close residual gaps (2026-05-30) |
| ADR-0917 | cargo-deny supply-chain policy enforcement |
| ADR-0996 | eBPF FUSE bypass for rclone zero-copy path in vmafx-node |
| ADR-1035 | CI workflow concurrency guards and job timeouts |
| ADR-1036 | Correct SPDX license identifiers and add missing libsvm copyright |
| ADR-1129 | Align release containers with the published tag and runtime ABI |
| ADR-1145 | Derive the Intel NEO compute stack (gmmlib and IGC) dynamically from pinned compute-runtime release metadata |
| ADR-1178 | Dev container image publication and release artifact container enforcement |
| ADR-1200 | The dev container falls back to the GitHub mirror for nv-codec-headers |
| ADR-1201 | Cut release candidates before the final 1.0.0 |
| ADR-1247 | Bind Scorecard gates to their measured source and scope |
| ADR-1271 | Pass NEO GitHub credentials through optional BuildKit secrets |
| ADR-1305 | Hash-locked Python dependency installs and OpenSSF supply-chain hardening |
| ADR-1314 | Keep unpinned Semgrep registry results advisory |
| ADR-1343 | Statically check that every dev-container stage copies the files it reads |
| ADR-1344 | Leave [project].version out of the Python lock input fingerprint |
| ADR-1346 | Build native release artifacts on a hosted runner inside the build-deps container stage |
| ADR-1347 | Recover a release's container images with the default branch's build recipe |
| ADR-1354 | Build the native Linux bundle on the Debian 13 release track |
| ADR-1356 | Release provenance from GitHub build-provenance attestations, not slsa-github-generator |
| ADR-1368 | Build and run the oneAPI release image on Debian 13 with pinned Intel packages |
| ADR-1493 | macOS tester bundle, an exception to container-only publishing |
| ADR-1503 | Every published tester artifact carries its licence texts, an attested SPDX SBOM and the source its copyleft parts require, and a gate refuses a file with no recorded licence |
| ADR-1513 | The production images, release assets and Python packages follow the tester licensing rules, checked by the same tool |
| ADR-1514 | The Go service images record every linked module's licence from the binary, and the node image ships a redistributable FFmpeg, a source-built rclone and the records of the libraries it copies |
| ADR-1515 | A native Windows tester zip for x64 and Arm64, built by the hosted runners with MSVC and a static C runtime |
| ADR-1517 | The production GPU images are built on Debian 13, ship only the vendor files libvmaf loads, and share the tester images' licence records |
| ADR-1539 | vmafx-node starts the eBPF descriptor tracker on request, fails closed when the host cannot run it, and ships the compiled BPF object |
| ADR-1546 | The registry validator holds tiny-model metadata to the shipped graphs |
| ADR-1559 | the node's eBPF program stays EUPL-1.2 and declares "GPL" to the kernel under EUPL-1.2's compatibility clause |
| ADR-1564 | The dev container is pushed only into a private package, checked before every push |
| ADR-1578 | The rc.1 and rc.2 ROCm and node images are withdrawn; every other published rc image gets notices and a source companion |
| ADR-1589 | the Helm chart deploys vmafx-controller as its own one-replica workload, and the release publishes a licence-gated controller image |
| ADR-1595 | Build and run what the push-only and release-only workflows publish, before they publish |
| ADR-1622 | the node's eBPF object is generated at build time with a pinned clang and no object is committed |
| ADR-1687 | Require the pull-request release legs through the aggregator |
| ADR-1805 | Delete the Netflix release tags inherited by VMAFx/vmafx |
| ADR-2126 | Declare the single-maintainer gaps of OpenSSF Scorecard's Code-Review and Branch-Protection checks as exceptions |
| ADR-2198 | A tester leg builds where its inputs change, and no release is cut on a leg nobody saw green |
| ADR-2321 | Move the praetor pin to afb739ed81f3 and meet its nested-context, supply-chain and harness checks |
| ADR-2350 | The VMAFx platform keeps its state in PostgreSQL, scales on queue depth and generates its platform surfaces from a definition |
| ADR-2383 | macOS and Windows package channels are fed by the verified native release pipelines |
| ADR-2705 | formulas are TeX rendered by self-hosted KaTeX, checked at build time |