Skip to content

Navigation Menu

Sign in
Sign up

Record SEC-LIC-001 against the licensing status - #5

Merged
PortixOne merged 1 commit into
master from
sec-lic-001-docs
Jul 16, 2026
Merged

Record SEC-LIC-001 against the licensing status #5
PortixOne merged 1 commit into
master from
sec-lic-001-docs

Conversation

@PortixOne

@PortixOne PortixOne commented Jul 16, 2026

Copy link
Copy Markdown
Collaborator

Corrects the licensing status doc, which read as though the fail-closed keyring was fully closed.

It isn't: the development keyring ships inside the production artifact, so PORTIX_LICENSE_ENV=development can still reach an authority whose private key is public. Fail-closed by default is not the same as unreachable.

Blocks Creator GA. Does not block internal pilots — see #4 and runtime-v0.1.0.

🤖 Generated with Claude Code

The hardening section claimed the fail-closed keyring as done. It is only partially done: the logic never makes the development key authoritative by default, but the development keyring still ships inside the production artifact, so an explicit PORTIX_LICENSE_ENV=development can still reach an authority whose private key is public. Fail-closed by default is not the same as unreachable, and the status should not read as if it were. Blocks Creator GA, not internal pilots.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
PortixOne merged commit c5de342 into master Jul 16, 2026
PortixOne deleted the sec-lic-001-docs branch July 16, 2026 20:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

1 participant

AltStyle によって変換されたページ (->オリジナル) /