Skip to content

Publish stable receipt schemas and a reusable model-eol verify command #78

Description

@thossullivan

Problem

0.5 produces content-bound evaluation, feed-refresh, and npm-release receipts, but their contracts and verifiers are workflow-internal. Consumers need a portable way to validate and reuse that evidence.

Scope

  • Publish canonical Draft-07 schemas for evaluation, refresh, and release receipts.
  • Add model-eol verify RECEIPT with explicit inputs for commit, plan, config, feed, and package bindings.
  • Distinguish structural validity from claims that were actually verified.
  • Version receipt formats and document compatibility behavior.

Acceptance / UAT

  • Genuine plan/evaluate/publish and refresh artifacts verify outside the source checkout using the packed npm package.
  • Tampering with commit, plan/config/feed digests, release commit, or package SRI fails.
  • Unsupported versions or missing material never produce a misleading verified result.
  • Hosted schemas pass exact-byte public-contract checks.
  • Node 22 packed-consumer tests pass with zero dependencies.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions