Immutable
release. Only release title and notes can be modified.
Skill Provenance 6.3.0
This release makes Skill Provenance easier to cite, evaluate, discover, and
adopt without overstating its trust model.
Highlights
- Adds schema-valid
CITATION.cffmetadata without claiming an unresolved DOI. - Defines a reproducible verified-adoption evidence contract and expands the
compatibility issue form to accept adoption reports. - Classifies canonical source, stable release assets, derived transports,
repository entry points, and separately published registry copies. - Records a read-only per-control OpenSSF-style baseline without presenting it
as an official Scorecard or publishable badge. - Expands coverage to 42 core plus 21 supplemental evals, 63 total.
- Makes the release-surface gate reject unexpected
.skillarchive entries.
Verification
- Signed release commit:
3d5c0c3ac2b5a211ff9b5db31534c8a2dea252db - Signed annotated tag:
v6.3.0 skill-provenance.skillSHA-256:
fff26e3b4238357ea4deccec25e53309c95b2b077ce96085adf39e95c5880b2f- Canonical hash validation, archive agreement, search contract, CodeQL,
citation schema validation, and executable regression gates passed.
Publisher signatures establish artifact identity, not skill safety. Review the
source, trust boundaries, and changelog before installation.