Skip to content

Pack signing and trust tiers #466

Description

@charneykaye

Cryptographic signing for packs so the validator can distinguish first-party content from unverified community submissions and enforce trust levels (e.g. official / verified creator / unsigned). Only meaningful once the community pack browser exists — sequenced after it.

Acceptance

  • Official packs ship signed; validator surfaces tier at import and in the library UI
  • Unsigned packs still importable with a clear warning (local-first: the user decides)
  • Signature scheme documented in docs/pack-validation.md

From docs/post-alpha-issues.md item 10 (Milestone 3 — community). Blocked by the community pack browser.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:packsScenario packs, schemas, validation, Creator Workbencharea:safetySafety policy, privacy, security, local-first guaranteesenhancementNew feature or improvementmanualPrevents vibrator from automatically picking up this issuepriority:P2Nice-to-have — post-launch or opportunistic

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions