Artifact identity
| Field | Value | Canonical record |
|---|---|---|
| Artifact type | Acceptance evidence statement JSON | — |
| Test suite | tools/build_site.py and tools/package_release.py preflight | — |
| Test environment | Deterministic build manifest and package preflight | — |
| Reviewer class | repository-automated | — |
| Certification status | Not independent certification | — |
| Generated | 2026-08-06 | — |
Published artifact: /docs/proof/assurance/evi-ae-016-v1.6.0-package-inventory.json
SHA-256: 78c067f52947db6a35f9e5d07b654f97e3725cacae3730ccc5f11f57ca3080c4
Scope and result
Result: PASS
Root source shape, safe paths, manifest-bound public inventory, required assurance-governance and durable records, and explicit final-archive checksum boundary.
Supported claims
Limitations
- The final ZIP checksum is external to the archive to avoid self-reference.
- Final archive replay is reported in the separately delivered package audit.
- No deployment or host extraction result is asserted.
Lifecycle
Supersedes
Invalidation conditions
- Hash mismatch
- Manifest or required-path mismatch
- Post-evidence source mutation
- Failed final package replay
Revision history
| Revision | Date | Change |
|---|---|---|
| 1.0 | Published the v1.6.0 release-source inventory evidence statement. |
Authority and record status
Responsible authority: National Engineering Directorate.
The hash establishes artifact identity only. The evidence remains bounded by its stated environment, method and limitations.
Revision date: . Public corrections may be initiated through the diplomatic contact route.