Repository navigation
v2.1.0 - Evidence anti-forgery + whole-bundle seal
v2.1.0
Evidence bundles go from tamper-evident to tamper-proof, plus a compliance-receipt fix. (PR #33)
Anti-forgery (opt-in)
_sign_bundleembeds the signer public key (self-contained bundles).verify_bundle_chain(trusted_fingerprints=, trusted_keys=, require_signature=)verifies asymmetric signatures overcanonical_json(bundle - signatures), trusting only a fingerprint recomputed from the key bytes (or akey_idin a caller's trusted set). HMAC never counts. Newattestation_keyaction input.
Integrity
- Whole-bundle keyless
bundle_hashseal (covers summary/analysis/context); downgrade guard requires the seal for any sealed-class bundle;seal_bundlewon't silently drop signatures.
Compliance
- SOC 2 / HIPAA / PCI control category + name now rendered in the receipt (not "general").
Verified: full suite 290 green; cross-verified against guardspine-kernel-py; crucible (4 Codex rounds CLEAN + 6-lens red-team, no forgery). Backward-compatible.
🤖 Generated with Claude Code