Problem
0.5 produces content-bound evaluation, feed-refresh, and npm-release receipts, but their contracts and verifiers are workflow-internal. Consumers need a portable way to validate and reuse that evidence.
Scope
- Publish canonical Draft-07 schemas for evaluation, refresh, and release receipts.
- Add
model-eol verify RECEIPT with explicit inputs for commit, plan, config, feed, and package bindings.
- Distinguish structural validity from claims that were actually verified.
- Version receipt formats and document compatibility behavior.
Acceptance / UAT
- Genuine plan/evaluate/publish and refresh artifacts verify outside the source checkout using the packed npm package.
- Tampering with commit, plan/config/feed digests, release commit, or package SRI fails.
- Unsupported versions or missing material never produce a misleading verified result.
- Hosted schemas pass exact-byte public-contract checks.
- Node 22 packed-consumer tests pass with zero dependencies.
Problem
0.5 produces content-bound evaluation, feed-refresh, and npm-release receipts, but their contracts and verifiers are workflow-internal. Consumers need a portable way to validate and reuse that evidence.
Scope
model-eol verify RECEIPTwith explicit inputs for commit, plan, config, feed, and package bindings.Acceptance / UAT