Zaibatsu v1.9.0 — Signed Runtime Evidence
·
24 commits
to main
since this release
Immutable
release. Only release title and notes can be modified.
Zaibatsu v1.9.0 adds evidence-gated ingestion of externally supplied OpenSSH Ed25519 verifier assertions.
Highlights:
- Content-addressed verifier registry with exact scope, requirement, method, and validity allowlists.
- Signed runtime-evidence verification plus deterministic, explicitly timed assessment.
- Rebuild DAG v2 binds the verifier registry, signed evidence, and combined assessment without granting execution or activation.
- Public fixture demonstrates signature, provenance, replay, freshness, and trust-boundary checks while remaining permanently runtime-ineligible.
- 194 adversarial tests and 87-file repository validation.
Trust boundary: a valid signature authenticates the assertion payload; it does not prove key ownership, verifier independence or correctness, artifact truth, deployment, execution, or activation authority.