Supply-Chain Hardening Suite

Purpose

The supply-chain hardening suite provides deterministic negative-path and mutation testing for scanner/attestor/symbols evidence workflows without requiring external network calls.

Working location:

Lanes

  1. 01-jcs-property
  1. 02-schema-fuzz
  1. 03-rekor-neg
  1. 04-big-dsse-referrers
  1. 05-corpus

Execution Profiles

  1. PR / push gate profile (smoke)
  1. Nightly profile (nightly)

Commands

  1. Run smoke profile:
  1. Run nightly profile:
  1. Rebuild corpus archive metadata:

CI Integration

Workflow:

Outputs:

Failure Replay

  1. Download CI artifact supply-chain-hardening-<run-id>.
  2. Read failing lane diagnostics under failures/<case-id>/.
  3. Re-run locally with the same seed:

Advisory Traceability

AdvisorySprintCoverage
docs-archive/product/advisories/20260222 - Fuzz & mutation hardening suite.mddocs-archive/implplan/2026-03-03-completed-sprints/SPRINT_20260226_228_Tools_supply_chain_fuzz_mutation_hardening_suite.mdLanes 01 through 05 + CI gate