Repository object · task

Em 0014

Accepted task in the public catalog.

Source path
tasks/contracts/EM-0014.json
Media type
application/json
Object ID
em:task:sha256:9dd71bc74401b043b817c6b1e7df67a1e8ca8dd4b7e64b274de3567a3f14b03f
Content digest
350ea0c9e2c7f3bb7f512fd00bc4380a19e2a728ff5a9c0d54f33e1731ab38c5

Source content

{

"$schema": "https://epistemedia.com/schemas/task-contract-v1.json",

"id": "EM-0014",

"title": "Bound the container context and preserve accepted release identity",

"status": "ready",

"change_class": "ordinary-implementation",

"objective": "Prevent local, secret, VCS, cache, and disposable state from entering the container build context while preserving the exact accepted commit and source timestamp in images built from an authorized release tag.",

"depends_on": [

"EM-0013"

],

"authority": {

"allowed_paths": [

".dockerignore",

".github/workflows/container.yml",

"Dockerfile",

"compose.yaml",

"src/**",

"tests/**",

"docs/**",

"ops/**",

"runs/**"

],

"forbidden_paths": [

"constitution/**",

"schemas/**",

"policies/**",

"catalog/**",

"governance/events/**",

"tasks/contracts/EM-0001.json",

"tasks/contracts/EM-0002.json",

"tasks/contracts/EM-0003.json",

"tasks/contracts/EM-0004.json",

"tasks/contracts/EM-0005.json",

"tasks/contracts/EM-0006.json",

"tasks/contracts/EM-0007.json",

"tasks/contracts/EM-0008.json",

"tasks/contracts/EM-0009.json",

"tasks/contracts/EM-0010.json",

"tasks/contracts/EM-0011.json",

"tasks/contracts/EM-0012.json",

"tasks/contracts/EM-0013.json"

]

},

"required_evaluation": [

"container build-context and secret-exclusion audit",

"accepted commit and source timestamp fallback tests without Git metadata",

"release-tag workflow identity propagation review",

"container build and endpoint smoke test when a Docker-compatible daemon is available"

],

"acceptance": [

"the container context excludes VCS metadata, virtual environments, caches, editor state, local realms, secret-shaped environment files, and disposable build output",

"the runtime image does not require or contain the repository Git directory to report its accepted commit and source timestamp",

"explicit build identity is validated and takes precedence only when repository Git metadata is unavailable",

"the protected container workflow derives commit and timestamp from the verified release tag and passes them into the image build",

"an untagged or malformed production identity cannot silently become a claimed accepted release",

"the existing non-root runtime, bounded request controls, read-only deployment posture, provenance, and SBOM configuration remain intact",

"make check passes without changing accepted source state"

],

"limitations": [

"This task does not create a release tag, publish an image, or activate a hosted API or MCP endpoint.",

"If a Docker-compatible daemon is unavailable, static and Python-level evidence must record that limitation and an actual image smoke test remains a pre-publication gate.",

"Registry identity, version selection, and the first irreversible package or container publication remain owner-gated."

]

}

Build receipt

Reproduce this projection

Reproducible projection
Catalog
em:catalog:sha256:9bfc972213cba2cde167386103dc2c011ee74639fb7f0794c54120fbbdef1a5d
Frontier
em:frontier:sha256:f33be3eae4c75232d56750ef9a1aa79d96274ece3417d65a75c1391bf61a81bf
Accepted commit
f92846570180dfa4511263f8ba98ecd18f7772c9
Epistemic policy
commons-balanced-v0.1
Disclosure policy
public-noninterference-v0.1
Compiler
epistemedia/0.2.0