Problem / motivation
Secure Tools needs the immutable secure-metadata v0.1.0 browser release without weakening its same-origin dependency boundary.
Scope
Download the v0.1.0 GitHub Release browser artifact to a temporary directory, verify SHA-256 locally and against SHA256SUMS, then vendor the unchanged artifact with tag-sourced LICENSE/package metadata and an adjacent provenance README. Extend the release gate.
Non-goals
No rebuild, npm/CDN/runtime fetch, source map, tarball, source tree, automatic update, or Secure_Metadata change.
Acceptance criteria
- The vendored browser artifact SHA-256 is exactly 8d0b8a1addf904760aa1f52378fb05eed6540520cb05fe2320d77011cba69c28.
- Approved vendor files, name, version 0.1.0, MIT license, tag, commit, artifact, and hash are pinned by tests.
- Runtime import remains same-origin and the artifact bytes are unchanged.
Problem / motivation
Secure Tools needs the immutable secure-metadata v0.1.0 browser release without weakening its same-origin dependency boundary.
Scope
Download the v0.1.0 GitHub Release browser artifact to a temporary directory, verify SHA-256 locally and against SHA256SUMS, then vendor the unchanged artifact with tag-sourced LICENSE/package metadata and an adjacent provenance README. Extend the release gate.
Non-goals
No rebuild, npm/CDN/runtime fetch, source map, tarball, source tree, automatic update, or Secure_Metadata change.
Acceptance criteria