Skip to content

Sprint 15.1 — Vendor and pin secure-metadata v0.1.0 #22

Description

@maruson08

Problem / motivation

Secure Tools needs an auditable, immutable browser metadata dependency without npm, CDN, rebuild, or runtime network loading.

Scope

Download the v0.1.0 GitHub Release browser artifact and checksum manifest, verify SHA-256, and vendor the unchanged artifact with tag-sourced LICENSE, package metadata, and provenance README.

Non-goals

No rebuild from Secure_Metadata main, source tree, tarball, source map, updater, or runtime fetch.

Acceptance criteria

  • Vendored browser artifact SHA-256 is exactly 8d0b8a1addf904760aa1f52378fb05eed6540520cb05fe2320d77011cba69c28.
  • Vendor directory contains only the approved four files.
  • README records version, tag, release commit, artifact, hash, license, dependency count, integration, and upgrade policy.
  • Release-gate tests detect binary and provenance drift.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions