string-audit v0.2.0 — real cas/anchored-chain + keyed Anthropic
Wires up the real published bounded-systems packages and a live keyed CI path.
cas + anchored-chain are real now (from JSR)
@bounded-systems/cas— content addressing (sha256Hex/sha256BareHex); blobs by digest,getre-hashes + rejects corrupt.@bounded-systems/anchored-chain— each cached result records a real in-toto derivation (digestManifest→derivationId,manifestToStatement→ anin-toto.io/Statement/v1), serialized withcanonicalJson.STORE=cas(andSTORE=socket, the room daemon) now produce canonical, in-toto provenance — verified in CI (the room step audits through the socket-mounted cas store).- (DSSE ed25519 signing —
assembleEnvelope+ed25519Signer— is the small remaining follow-up.)
Live keyed Anthropic — in Actions
.github/workflows/anthropic.yml: manual + weekly live audit gated on theANTHROPIC_API_KEYrepo secret (real LLM only on cache-miss). Add the secret to enable.
Unchanged & green
fs / cas / socket-in-a-room stores · typed audits · grounding guard · spell + custom dictionary · grammar · overlap · extract+coverage · Anthropic path test. CI pipeline green.