Central Vault Sync 0.1.22
Community-review compatibility release with artifact attestations temporarily omitted.
- Retains all sync behavior from 0.1.21 unchanged.
- Retains lightweight tags, unique per-release asset digests, reproducible source builds, exact asset/source byte comparison, and fail-closed release checks.
- Temporarily omits GitHub artifact attestations because Obsidian's current scorecard rejects newly issued attestations—including v3 and v4 bundles that GitHub verifies successfully—as hard errors.
- Missing attestations are represented by the Community scorecard as a non-blocking disclosure rather than an invalid-signature risk.
This is limited to the Community-review 0.x release. Stable-release provenance remains an acceptance requirement and will be restored after verifier compatibility is established.
Verification: lint, typecheck, 31 tests, production build, policy checks, lightweight tag, exact release/source bytes, and published SHA-256 digests.