Record
| Field | Value | Canonical record |
|---|---|---|
| Claim type | Release-package assurance | — |
| Classification | PUBLIC | — |
| Reviewer class | repository-automated | — |
| Certification status | Not independent certification | — |
| Test environment | Deterministic ZIP creation and independent archive replay in the release workspace | — |
| Publication date | 2026-08-05 | — |
Method and result
Method: tools/package_release.py builds a deterministic archive, reopens it, checks every path and replays every entry hash against the source inventory.
Result: PASS when the versioned release archive and audit are emitted by the accepted packaging run.
Supporting evidence
Limitations
- The final ZIP checksum is external to the archive to avoid self-reference.
- Package integrity does not prove upload, extraction or host behavior.
- Any post-package file change requires a new versioned archive and audit.
Relationships
System: EVI-SYS-EVULGARE-001 — Evulgare
Doctrine: EVI-DEF-001
Superseded by
Review, coverage and expiry
No review-governance record is registered.
Validity and invalidation
- Any mismatch between release files, public manifest, ZIP inventory or audit
- Unsafe or duplicate archive paths
- Failure of per-entry hash replay
Revision history
| Revision | Date | Change |
|---|---|---|
| 1.0 | Published the deterministic package-integrity claim and self-reference boundary. | |
| 1.1 | Revalidated the v1.5.0 release-source inventory and explicit checksum self-reference boundary. | |
| 1.2 | Superseded by EVI-AC-012 after the v1.6.0 change-impact review; prior scope and evidence remain preserved. |
Authority and record status
Responsible authority: National Engineering Directorate.
This claim is governed by EVI-PRO-015 and is explicitly not independent certification.
Revision date: . Public corrections may be initiated through the diplomatic contact route.