Skip to content

fix(evidence): actionable error when verify reads a corrupt bundle - #426

Merged
vibgrate-team merged 3 commits into
mainfrom
cursor/evidence-verify-corrupt-bundle-4df1
Oct 10, 2026
Merged

vibgrate-team merged 3 commits into
mainfrom
cursor/evidence-verify-corrupt-bundle-4df1

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg evidence verify used to JSON.parse the envelope and result directly, so a truncated file, invalid JSON, or a document that is not an evidence bundle surfaced a raw parser error.

Verification now loads the bundle first. A truncated or invalid envelope or result, or a schema this version cannot read, fails with a stable error and exit code 1. The message names the envelope or the result and says to restore the bundle or re-create it with vg evidence exposure --bundle. It does not include file contents, parser excerpts, environment values, or a stack.

A missing bundle is still "not found" (exit 3), and a readable bundle still reports verified, unverified or failed.

Related issues

Closes #287

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated where behavior changed
  • Determinism preserved
  • No proprietary or internal references
  • Commits use Conventional Commits and are signed off

How to verify

pnpm test
pnpm lint
pnpm typecheck

cursoragent and others added 3 commits October 9, 2026 22:02
Truncated, invalid JSON, and schema-broken evidence bundles now fail
vg evidence verify with a stable operator error and a non-zero exit.
The message names the failure and does not include bundle contents.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
vg evidence verify exits 1 when the envelope or result.json is
truncated, not JSON, or not a document this version can read. The
message says what failed and how to restore the bundle. It does not
print a stack or the file contents. A readable bundle still reports
verified, unverified, or failed.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Signed-off-by: Cursor Agent <cursoragent@cursor.com>

# Conflicts:
#	CHANGELOG.md

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
@vibgrate-team
vibgrate-team marked this pull request as ready for review October 10, 2026 22:57
@vibgrate-team
vibgrate-team merged commit 524a1de into main Oct 10, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: actionable error when vg evidence verify reads a truncated or corrupt bundle

2 participants