Skip to content

Skill Provenance 7.0.0

Latest

Choose a tag to compare

@snapsynapse snapsynapse released this 24 Sep 04:13
· 1 commit to main since this release
Immutable release. Only release title and notes can be modified.
v7.0.0
faf6b58

Skill Provenance 7.0.0

This release makes the manifest inventory complete. Before 7.0.0, a bundle
containing a file that MANIFEST.yaml did not list still verified with exit 0,
so an added script could pass integrity verification.

Breaking change

validate.sh now fails (exit 1) when anything beneath the bundle root is not
listed in MANIFEST.yaml. Bundles that previously passed with extra files,
including stray .DS_Store files, now fail. List the file in the manifest or
remove it. For a bundle that intentionally shares its directory with other
files, such as a skill at a repository root, --allow-unlisted reports those
entries as warnings and exits 0 without verifying them.

Highlights

  • Reports every unlisted file, symlink, or special file as UNLISTED. Only
    the root MANIFEST.yaml is exempt.
  • Never follows unlisted symlinks and never reads special files.
  • Escapes control characters in reported names so a crafted filename cannot
    forge an OK line.
  • Fails closed on a directory it cannot enumerate.
  • --update never adds unlisted files to the manifest.
  • Remains zero-dependency and compatible with macOS system Bash 3.2.
  • Expands coverage to 43 core plus 21 supplemental evals, 64 total.

Verification

  • Signed release commit: faf6b58c43a403ac62f8516c2b84ba8d36c53e3c
  • Signed annotated tag: v7.0.0
  • skill-provenance.skill SHA-256:
    aa8acf27976fb220cd9f3ddb04dfa02da4b44481fa3ff4d4905ebd2e5944a522
  • Canonical hash validation, complete-inventory regression tests under Bash
    5.3 and 3.2, derived package validation, standalone verifier pinning, action
    input transport, archive agreement, and search contract passed.

Publisher signatures establish artifact identity, not skill safety. Review the
source, trust boundaries, and changelog before installation.