Skip to content

docs: finalize fixture canary evidence - #5

Merged
zsumz merged 1 commit into
mainfrom
agent/finalize-fixture-canary
Aug 9, 2026
Merged

docs: finalize fixture canary evidence#5
zsumz merged 1 commit into
mainfrom
agent/finalize-fixture-canary

Conversation

@zsumz

@zsumz zsumz commented Aug 9, 2026

Copy link
Copy Markdown
Owner

What changed

  • replaces every staged-canary PENDING field with verified publication evidence
  • records the npm trusted publisher, 2FA approver, public integrity, and finalizer artifact
  • records the immutable GitHub prerelease and successful replay-safe no-op
  • documents independent byte identity across the candidate, npm, and GitHub tarballs

Why

The acceptance record should close only after the public registry bytes,
provenance, GitHub bundle, and replay behavior have been independently checked.

Validation

  • git diff --check
  • npm run release:check
  • public npm and GitHub tarballs compared byte for byte with the sealed candidate
  • finalizer replay 31339527592 completed as a verified no-op
  • commit verified as OpenPGP-signed by zsumz <shawn@zsumz.com>

@zsumz
zsumz marked this pull request as ready for review August 9, 2026 22:34
@zsumz
zsumz merged commit ae38846 into main Aug 9, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant