Repository navigation
Releases: MIKTHATGUY/momento
Release list
Momento 2.0.0 — Post-quantum receipts and Git attestations
Momento 2.0.0 adds post-quantum timestamp receipts and Git history attestations.
Breaking migration
Receipt signatures now use ML-DSA-65 (FIPS 204) and protocol v2. Updated verifiers reject all Ed25519 keys and v1 receipts, with no classical fallback. Discard old keys, upgrade the CLI, protocol package, Action and saved offline verifiers, and re-timestamp original files for new receipts. Old issuance times cannot be recovered as post-quantum proofs. API endpoints are now /api/v2/stamp, /api/v2/verify, and /api/v2/keys.
Self-hosted installations must provision ML_DSA65_PRIVATE_KEY_BASE64URL, deploy the matching public key, then remove SIGNING_PRIVATE_KEY_BASE64URL. SHA-256 file fingerprints are unchanged. Quantum-resistant describes the signature algorithm; timestamp trust still depends on the service clock and signing key.
Git history attestations
- Local Git hooks link commit attestations to parent receipts and synchronize proofs through the hidden
refs/momento/proofsref. - Offline verification checks receipt signatures, exact commit bytes, parent links, merges and activation scope.
- The bundled GitHub Action supports
verify-historyand publishes coverage badges, including negative results.
Packages and service
- Standalone Node CLI and portable protocol package, both version 2.0.0 (Node.js 22.18+).
- Bounded receipts, network timeouts, signing readiness checks and public-key lifecycle metadata.
- Browser receipt sharing and local verification through URL fragments.
- Live GitHub release notes, static security headers, protocol specification and interoperability tests.
Downloads and npm availability
Attached package archives can be installed together locally:
npm install ./mikthatguy-momento-protocol-2.0.0.tgz ./mikthatguy-momento-timestamp-2.0.0.tgzSHA256SUMS and manifest.json describe the downloads. npm publication is delayed while account recovery awaits npm support; this GitHub release does not guarantee registry availability. Checkout-based instructions remain available in the documentation.