← policies

Policy of record

Independent verification

Every page names the exact release it was compiled from, and no one has to trust this site to check it.

The release graph is signed, content-addressed, and independently mirrorable. Any consumer can prove what the catalog said, when, from local bytes.

How to verify a release

  1. Fetch the machine twin, catalog.json. It carries the release ID, the artifact digest, and every record with its revision digest.
  2. Recompute any revision digest from the record's canonical bytes and compare. Each revision is content-addressed, so a single changed fact changes its digest.
  3. Follow a record's evidence bindings to their observation and capture digests. The bindings name the exact bytes, and the byte ranges, that support each field.
  4. Run the public repository's read-only reference verification command. It accepts only local bytes and pinned roots, and checks the signed manifest, the signer registry chain, and the object index without calling this site.

TLS, a hosting provider, or an API response is never the sole proof.

revision sha256:438ded8e46d5cdb8382bcd1ed5f50ff2af8bb4f26fbd99f3d716c714e534c157 · published in release sha256:9cc785230fab…