Skip to content

feat(action): add GitHub Action to verify audit CIDs (#51) - #80

Merged
Eras256 merged 1 commit into
nirium-protocol:mainfrom
Simultech369:feat/verify-audit-cid-action
Aug 28, 2026
Merged

Eras256 merged 1 commit into
nirium-protocol:mainfrom
Simultech369:feat/verify-audit-cid-action

Conversation

@Simultech369

Copy link
Copy Markdown
Contributor

Closes #51

Summary

Implements the actions/verify-audit-cid GitHub Action for deterministic CI verification of Nirium audit trail integrity.

Key Features & Implementation

  • Verifier semantics aligned with [Advanced] Standalone offline audit-CID + agent-attestation verifier (zero backend dependency) #38: Recomputes SHA-256(JSON.stringify(doc.record)), reconstructs nirium-audit-v1:<computedHash>, and never trusts embedded valid or agent.statement fields.
  • Ed25519 / Stellar signer verification: Decodes Stellar G... public keys with StrKey.decodeEd25519PublicKey and verifies the embedded Ed25519 agent signature.
  • Lean GitHub Action runtime: Uses standard GitHub Actions environment files for outputs and step summaries, avoiding @actions/core and its dependency surface.
  • Gateway handling: Supports configurable IPFS gateways, including bare gateway URLs and /ipfs/ gateway forms.
  • Pre-bundled distribution: Ships checked-in dist/index.js for zero-install workflow consumption.
  • CI workflow: Adds .github/workflows/test-verify-audit-cid.yml covering action tests, live CID verification, and a deliberate tampered-fixture failure path.

Validation

  • npm test -> 8/8 passing
  • npm audit --omit=dev --json -> 0 vulnerabilities
  • npm run package -> bundled dist/index.js
  • Live CID verification via Pinata gateway -> ok=true, hashMatch=true, signatureStatus=valid
  • Tamper coverage: altered record hash, forged signature, missing agent block, and statement-substitution attack

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Advanced] Reusable GitHub Action: verify a Nirium audit-CID in CI

2 participants