Skip to content

v2.1.0 - Evidence anti-forgery + whole-bundle seal

Choose a tag to compare

@DNYoussef DNYoussef released this 25 Jun 11:23
· 23 commits to main since this release

v2.1.0

Evidence bundles go from tamper-evident to tamper-proof, plus a compliance-receipt fix. (PR #33)

Anti-forgery (opt-in)

  • _sign_bundle embeds the signer public key (self-contained bundles).
  • verify_bundle_chain(trusted_fingerprints=, trusted_keys=, require_signature=) verifies asymmetric signatures over canonical_json(bundle - signatures), trusting only a fingerprint recomputed from the key bytes (or a key_id in a caller's trusted set). HMAC never counts. New attestation_key action input.

Integrity

  • Whole-bundle keyless bundle_hash seal (covers summary/analysis/context); downgrade guard requires the seal for any sealed-class bundle; seal_bundle won't silently drop signatures.

Compliance

  • SOC 2 / HIPAA / PCI control category + name now rendered in the receipt (not "general").

Verified: full suite 290 green; cross-verified against guardspine-kernel-py; crucible (4 Codex rounds CLEAN + 6-lens red-team, no forgery). Backward-compatible.

🤖 Generated with Claude Code