# Release provenance locks

Every tag pipeline requires a reviewed lock named
`release/provenance-<tag>.json`, for example
`release/provenance-v1.3.0.json`. The lock binds the tag version to exact
upstream versions, URLs, BLAKE3 digests, and human-review evidence. Release CI
does not call upstream “latest” APIs.

Copy `provenance.example.json`, replace every placeholder, verify each upstream
artifact through its strongest available upstream/native signature or a
separately obtained checksum, and commit the lock through review before the
tag is created. The tag pipeline downloads each URL and rejects any byte that
does not match the reviewed digest. Extra or unused lock entries also fail the
pipeline.

The six MPV Manager binaries are not listed here. Their hashes and sizes are
computed directly from the build-job artifacts in the same pipeline.

The application project does not own `MANIFEST_SIGNING_KEY`. It sends the
unsigned candidate and this lock to the isolated signing service using a
short-lived GitLab OIDC token. The service must independently validate:

- issuer, audience, project ID, protected tag/ref, commit SHA, pipeline ID,
  token expiry and one-time `jti`;
- exact lock schema, review policy, tag/version binding, and artifact digests;
- the candidate's canonical content against the lock and pipeline-local
  manager artifacts;
- monotonic stable-channel publication policy.

The signer must have no general outbound network path, use a non-exportable
key where available, and return only the signed manifest. Remove legacy
`MANIFEST_SIGNING_KEY` and `MANIFEST_SIGNING_KEY_ID` variables from this
project; CI deliberately fails if either is still present.
