Skip to content

build: add capsec capability-security tokens to CLI and infra adapters#103

Draft
bordumb wants to merge 1 commit intomainfrom
devCiworkflows
Draft

build: add capsec capability-security tokens to CLI and infra adapters#103
bordumb wants to merge 1 commit intomainfrom
devCiworkflows

Conversation

@bordumb
Copy link
Copy Markdown
Contributor

@bordumb bordumb commented Mar 25, 2026

Thread capsec SendCap tokens through the CLI boundary into all I/O
adapters (filesystem, network, subprocess). This is plumbing-only:
tokens are minted at the entry point and passed to adapter constructors
to make I/O permissions explicit in the type system. Actual enforcement
is limited to FileConfigStore and LocalFileArtifact; git2 and reqwest
adapters hold tokens as documentation markers for now.

   Thread capsec SendCap tokens through the CLI boundary into all I/O
   adapters (filesystem, network, subprocess). This is plumbing-only:
   tokens are minted at the entry point and passed to adapter constructors
   to make I/O permissions explicit in the type system. Actual enforcement
   is limited to FileConfigStore and LocalFileArtifact; git2 and reqwest
   adapters hold tokens as documentation markers for now.
@bordumb bordumb self-assigned this Mar 25, 2026
@bordumb bordumb marked this pull request as draft March 25, 2026 01:53
@vercel
Copy link
Copy Markdown

vercel bot commented Mar 25, 2026

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
auths Ready Ready Preview, Comment Mar 25, 2026 1:53am

@github-actions
Copy link
Copy Markdown

Auths Commit Verification

Commit Status Details
65d4f7c0 ✅ Verified Signed by z6MktnihicwetvA16FtHFynaJTn9eDZw51eizUEA1yGJCR4o@auths.local

Result: ✅ 1/1 commits verified

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant