Skip to main content

szl-ci-witness

PyPI Python

CI as witness. Each witnessed non-PR workflow run appends one hash-chained receipt to ci-witness.jsonl: repo, commit, run id, conclusion, test counts, python version, timestamp — chained to the previous run. Anyone can recompute the chain offline. Regressions and fixes are detected from the linkage, not from dashboards.

Why

The next run restores the preceding Actions artifact, verifies its hashes and terminal run provenance, and appends measured JUnit test outcomes. Changing existing content without rehashing fails verification. Failures are recorded as well as successes.

Usage in any repo

Use the SHA-pinned, complete pattern in .github/workflows/tests.yml. It grants only contents: read and actions: read, serializes runs per workflow/ref, separates Python-version streams, and retains artifacts for 90 days. queue: max retains up to 100 pending runs rather than replacing the single pending run under the default concurrency behavior. Consumer repositories must pin this package to an exact reviewed commit. Pull requests and tag dispatches run tests but do not publish trusted branch history.

For each non-PR run:

  1. Set WITNESS_STREAM to workflow-name:refs/heads/branch:python-X.Y.
  2. Restore using python -m szl_ci_witness.github_artifacts with the scoped Actions token in GH_TOKEN; retain the step's artifact_name output.
  3. Run pytest with --junitxml=test-results.xml.
  4. Use python -m szl_ci_witness.witness record-junit --conclusion with the test step's actual outcome, including when tests fail.
  5. Verify and upload ci-witness.jsonl plus test-results.xml using the restore step's artifact name, even after test failures.

The recorded scope is test-step outcome, not an assertion that every workflow job succeeded. Never substitute guessed counts or a dashboard color for the JUnit report. The legacy record command accepts caller counts; record-junit is the measured CI path.

record reads GITHUB_REPOSITORY, GITHUB_SHA, GITHUB_RUN_ID from the Actions environment by default. The chain file commits or uploads as an artifact — either way it is verifiable:

python -m szl_ci_witness.witness verify    # linkage recompute
python -m szl_ci_witness.witness summary   # runs, green/red, regressions, fixes

Verified behavior (pre-push, 2026-09-04)

A four-run synthetic chain (green, green, red, green) yields exactly regressions: [102] and fixes: [103]; flipping one recorded conclusion without re-hashing invalidates the whole chain; an empty chain fails closed. Persistence tests restore ZIP fixtures, preserve predecessor bytes, and reject mismatched repositories, branches, workflows, terminal source commits, expired predecessors, and API failures. Missing test reports cannot produce successful measured counts.

Trust boundary

GitHub artifact storage is retention-bounded, not a permanent independent witness. When the latest matching artifact is expired or the API fails, restoration fails closed. An observed empty artifact inventory is labeled GENESIS_OBSERVED_NO_ARTIFACTS; it cannot prove that no artifacts were previously deleted. A fully rewritten and rehashed chain cannot be detected from that chain alone. Archive a trusted terminal hash and the full chain outside this repository for independent continuity assurance. Receipts are explicitly UNSIGNED_HONEST; GitHub origin checks do not turn them into cryptographic signatures or proof of production runtime health.

The chain covers runs which reached the witness step. Manual cancellation, setup failures, and queue overflow beyond GitHub's 100-pending-run limit may leave runs without receipts. Do not use chain length as proof that every trigger or source revision was witnessed. See the official GitHub concurrency contract.

Doctrine

  • Verify predecessors before appending; retain the preceding bytes.
  • Failures are recorded, never hidden.
  • Timestamps are reported, never backfilled.
  • Python 3.11+, standard library only.

License

Apache-2.0 — canonical org text (see LICENSE pointer).

Metadata

Release files for szl-ci-witness 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for szl-ci-witness 0.1.1
File Size Uploaded
szl_ci_witness-0.1.1.tar.gz 21.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for szl-ci-witness 0.1.1
File Interpreter ABI Platform
szl_ci_witness-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 35.0 kB

Release files / szl_ci_witness-0.1.1.tar.gz

Download URL szl_ci_witness-0.1.1.tar.gz
Size 21.1 kB
Tags Source
SHA-256 checksum
How to use checksums
1276250ad980d97d6a47ed36f2d5be4822b8a002cc3cafbd9feadff81b6c04ea
BLAKE2b-256 checksum
How to use checksums
3779fbaf31c06944c42a15bd793ec463791448c750cae000437a330bf8a5ea24
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / szl_ci_witness-0.1.1-py3-none-any.whl

Download URL szl_ci_witness-0.1.1-py3-none-any.whl
Size 13.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
49c85880d89de5fca2f401c336a13e50b2e722eb467493b10d058da7248adc20
BLAKE2b-256 checksum
How to use checksums
df9602da055bd5ef5ab43dfb041280237d6b9941d9fc262f9469076e6099568c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page