YUYuki Tanakacommented 3w ago
Summary
refactor(sentinel): land cosign + SBOM signatures for every release — addresses the regression surfaced in sentinel-graph after the recent refactor work landed on main.
Why
- The previous behavior on
mainshort-circuited the safe path under load; this PR restores the intended contract. - Adds a guard so the regression cannot resurface silently in staging.
- Drive-by: removes dead-code call sites the linter was warning about.
Scope
- Files touched: 24 across the core module + tests.
- No public API change; ABI is preserved.
- CI: all green on the matrix runs.
Labels: feature