An ADR captures a decision that is architecturally significant, security-sensitive,
or expensive to change later. Each ADR is immutable once accepted; a new ADR must
supersede it.
Proposed — draft, open for discussion
Accepted — decision is final and binding
Superseded — replaced by a later ADR (reference included)
Rejected — considered but not adopted (reasons recorded)
ADR Title Status Issue
0001 Rust 2024 and toolchain policy Accepted —
0002 Workspace structure and crate boundaries Accepted —
0003 reqwest behind Fetcher trait Accepted —
0004 TOML for configuration and policy Accepted —
0005 redb as non-authoritative metadata index Accepted #12
0006 Wasmtime Component Model for plugins Accepted —
ADR Title Status Issue
0007 Assurance levels model (inspect/mediated/contained) Accepted #2
0008 Execution context security profile Accepted #3
0009 Privilege separation and no-root invariant Accepted #4
0010 Platform provenance preservation Accepted #5
0011 Plugin trust classification model Accepted #6
0012 TUF implementation selection Accepted #7
0013 Plan-bound approval capability model Accepted #8
0014 Receipt canonicalization (RFC 8785 JCS) Accepted #9
0015 Safe destination release semantics Accepted #10
0016 Terminal and Unicode sanitization renderer Accepted #11
0017 Monotonic project configuration Accepted #13
0018 SSRF, proxy, and connected-peer verification Accepted #14
0019 catch_unwind and panic=abort interaction Accepted #80
0020 Seccomp-BPF network isolation for subprocess plugins Accepted #208
0021 Landlock filesystem isolation for subprocess plugins Accepted #209
0022 SLSA Build Level target for Arbitraitor releases Accepted #272
0023 in-toto Statement receipt envelope Accepted #273
0024 macOS containment strategy Accepted #279
0025 OpenSSF Scorecard, deps.dev, and GUAC as optional integrations Accepted #275
0026 EU CRA / NIST SSDF informational compliance mapping Accepted #276
0027 CLI inspect pipeline boundary Accepted #436
0028 Landlock ABI probe and receipt recording Accepted #466
0029 VEX format support matrix Accepted #468
0030 SBOM/VEX ingestion profiles (CISA 2025 minimum elements + SBOM-for-AI) Accepted #467
0031 OpenSSF malicious-packages feed via OSV.dev Accepted #474
0032 Tar parser consensus check Accepted #459
0033 Fetch cross-protocol credential secrecy Accepted #472
0034 Apple Containerization GA strategy for macOS 26+ Proposed #475
0035 LNK argument padding detection (CVE-2025-9491) Accepted #473
0036 run pipeline content-type execution gateAccepted #612
0037 Wasmtime CVE risk register Accepted #463
0038 Pipeline engine crate extraction and naming Proposed —
0039 Receipt envelope structure (spec §31.1) Accepted #492
# ADR NNNN: Title
**Status:** Accepted | Accepted | Superseded by ADR-XXXX | Rejected
**Date:** YYYY-MM-DD
**Issue:** #NN (GitHub issue this ADR resolves, if applicable)
## Context
Why this decision is needed.
## Decision
What was decided.
## Consequences
What follows from the decision.
## Alternatives considered
Options that were evaluated and rejected.
## References
Spec sections, advisories, standards, library docs.