Verifiable Agent Trust Envelope v0.3.0 - AL2 Evidence Reference Hardening Draft
Pre-releaseVerifiable Agent Trust Envelope v0.3.0 - AL2 Evidence Reference Hardening Draft
v0.3.0 is an AL2 verifier admission hardening discussion-draft pre-release.
This pre-release supersedes the archived v0.2.0 review snapshot for current main-branch review purposes. It does not mutate the v0.2.0 GitHub release or Zenodo archive artifacts.
Summary
The main machine-readable change in v0.3.0 is that AL2 admission requests now require at least one digest-addressed evidence_refs entry.
An empty evidence_refs array is schema-invalid and should fail closed with SCHEMA_INVALID and FAIL_CLOSED.
This release includes:
VATE-AL2-Verifier-Admission-v0.3- a 63-case AL2 v0.3 draft conformance corpus
- a fail-closed conformance case for empty
evidence_refs - v0.3 A2A-shaped metadata review documents
- v0.3 receipt, metadata, report, and SUT result schema alignment
- reference runner support for the v0.3 corpus
- package-private TypeScript helper packages
What implementers can test
Implementers can run their verifier against the v0.3 corpus, emit a SUT result file matching the repository schemas, and compare that result with the reference runner.
Passing the comparison means one SUT result matched one corpus snapshot under the repository comparison rules.
It does not grant a compatibility badge, certification, endorsement, production approval, or general compatibility claim.
Release boundary
This is:
- a discussion draft
- a conformance review aid
- an A2A-shaped metadata review package
- a reference runner and package-private helper set
This is not:
- production-ready
- certified or certification-ready
- an official A2A extension
- endorsed by A2A
- an SDK or A2A middleware package
- a production JOSE / PKI / JCS verifier
- a general compatibility proof
Verification
The full pre-release gate was run on:
830f15a5532690f63b158ad1efcab7015f778f41
Gate summary:
- working tree clean
- corpus case count:
63 - Python compile checks: pass
- repository sanity check: pass
- strict schema validation: pass
- v0.3 corpus run:
63 passed / 0 failed - SUT compare:
63 passed / 0 failed - implementation report generation:
63 passed / 0 failed - bundle verification:
23 passed / 0 failed - TypeScript check: pass
- TypeScript tests:
6 test files / 16 tests passed - npm audit, moderate or higher:
0 vulnerabilities - final external release-boundary review: GO, no P1 blockers
Citation and DOI
Before the v0.3.0 archive DOI exists, CITATION.cff remains pointed at the archived v0.2.0 snapshot.
For unarchived v0.3.0 work, cite the repository URL and exact commit SHA:
830f15a5532690f63b158ad1efcab7015f778f41
A separate citation patch should update CITATION.cff and README citation text after the v0.3.0 archive DOI is available.