Release v0.9.0
Summary
Give hosts an explicit, portable source mapping so generated evidence can retain stable project-qualified identity independently from the path shown to users. Existing SourceRoot consumers and generated output remain compatible.
Added
- Add immutable source-path policies, project source contexts, and typed stable file identities with fail-closed path validation. (#21)
- Add project-aware evidence APIs and deterministic canonical ordering for same-display files from different projects. (#21)