Source and disposition
- Correction record
- EVI-ERC-049
- Supplied source
- Automated Software Supply Chain Standard.md
- Source SHA-256
- dae9666fcc12f72366e14f5902e3f1041ba6de320999b0139a342459ec3b7276
- Active disposition
- CORRECTED_PUBLIC_EDITION
- Corrected repository edition
- /docs/long-term-memory/reports/automated-software-supply-chain-standard.md
The corrected durable edition is stored at /docs/long-term-memory/reports/automated-software-supply-chain-standard.md. The public route presents its governed correction record without exposing the blocked source body.
Correction summary
Removed the absolute claim that human trust models must be eradicated; the governing requirement is verifiable, role-separated evidence with accountable authority and review, regardless of whether an actor is human or machine. Removed unsupported incident and campaign references and treated all named supply-chain attacks as requiring source verification before public reuse. Corrected the implication that a short-lived SVID or hardware measurement makes key compromise practically impossible; it reduces some risks while leaving platform, policy, issuance, and physical threats. Separated signed provenance from reproducibility, deployment, runtime operation, legal authorization, and independent certification. Classified example manifests, hashes, signatures, versions, and deployment events as fixtures rather than current Eviulon release evidence.
Canonical corrections applied
- Removed the absolute claim that human trust models must be eradicated; the governing requirement is verifiable, role-separated evidence with accountable authority and review, regardless of whether an actor is human or machine.
- Removed unsupported incident and campaign references and treated all named supply-chain attacks as requiring source verification before public reuse.
- Corrected the implication that a short-lived SVID or hardware measurement makes key compromise practically impossible; it reduces some risks while leaving platform, policy, issuance, and physical threats.
- Separated signed provenance from reproducibility, deployment, runtime operation, legal authorization, and independent certification.
- Classified example manifests, hashes, signatures, versions, and deployment events as fixtures rather than current Eviulon release evidence.
Contribution retained
Useful research is preserved only through the corrected active edition and its bounded synthesis.
- Useful research is preserved only through the corrected active edition and its bounded synthesis.
Claims not adopted
No production SPIRE trust domain, TPM attestation fleet, independent rebuild organization, public transparency ledger, production signing key, or externally certified SLSA level is claimed.
- No production SPIRE trust domain, TPM attestation fleet, independent rebuild organization, public transparency ledger, production signing key, or externally certified SLSA level is claimed.
Raw-source boundary
The exact submitted bytes are preserved under the non-startup, non-public quarantine path and identified by the SHA-256 above. Active memory points only to the corrected edition, doctrine, and correction record. This separation preserves provenance while preventing the submitted report from silently redefining ecosystem roles.
Authority and record status
Responsible authority: State Registry and National Archive Authority.
Repository-local correction record; it does not validate external legal claims, live Patefacere behavior, Evulgare service delivery, or production deployment.
Revision date: . Public corrections may be initiated through the diplomatic contact route.