{
  "spec": "coderifts-atomic-stack-release.v1",
  "$comment": "commit, source_commit and generated_at are HEAD-derived at last --out. --check accepts them when the recorded commit is the current HEAD or an ancestor of it, and generated_at is that commit's committer date; anything else fails. Current HEAD: git rev-parse HEAD. Suite measurement: src/generated/test-count.json.",
  "generated_at": "2026-09-21T21:32:31+02:00",
  "commit": "b9e29de9df378e64a29436e892e60f6107205904",
  "source_commit": "b9e29de9df378e64a29436e892e60f6107205904",
  "frozen_release_set": {
    "spec": "coderifts.frozen-release-set.v1",
    "name": "release-set-2026-09-21b",
    "digest": "sha256:77a1976600b2547dc91aae7fca6cb13e7d2b0793f2dbf214882abc07e5a44a93"
  },
  "packages": {
    "cli": {
      "name": "coderifts",
      "main_version": "8.6.6",
      "version": "8.6.6",
      "published_version": "8.6.6",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "b9e29de9df378e64a29436e892e60f6107205904",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_cli to the tarball sha256 to record it",
      "source": "packages/cli/package.json",
      "bucket": "derived"
    },
    "guard": {
      "name": "@coderifts/agent-guard",
      "main_version": "17.3.5",
      "version": "17.3.5",
      "published_version": "17.3.5",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "5ba21f47e3f119c08f43b2dcb3058b9e3e50f956",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_guard to the tarball sha256 to record it",
      "source": "coderifts-agent-guard/package.json",
      "bucket": "derived"
    },
    "sdk": {
      "name": "@coderifts/sdk",
      "main_version": "3.14.2",
      "version": "3.14.2",
      "published_version": "3.14.2",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "3ea14dd79203e01b96fd0138c55a5a5aa0102b36",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_sdk to the tarball sha256 to record it",
      "source": "@coderifts/sdk package.json",
      "bucket": "derived"
    },
    "python": {
      "name": "coderifts-sdk",
      "main_version": "3.8.2",
      "version": "3.8.2",
      "published_version": "3.8.2",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "a4fdbe02cb6448b8a822b4742cb5d0211eebd7b9",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_python to the tarball sha256 to record it",
      "source": "coderifts-python-sdk/pyproject.toml",
      "bucket": "derived"
    },
    "gate": {
      "name": "coderifts/contract-gate",
      "main_version": "0.9.5",
      "version": "0.9.5",
      "published_version": "0.9.5",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "517a9964c59bf351f135a59a643c9adc978fc526",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_gate to the tarball sha256 to record it",
      "source": "coderifts-contract-gate/package.json",
      "bucket": "derived"
    },
    "conformance": {
      "name": "@coderifts/conformance",
      "main_version": "0.8.11",
      "version": "0.8.11",
      "published_version": "0.8.11",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "b59c9c56294e09c1918deda18245322084efc104",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_conformance to the tarball sha256 to record it",
      "source": "coderifts-conformance/package.json",
      "bucket": "derived"
    },
    "prove": {
      "name": "@coderifts/prove",
      "main_version": "0.1.13",
      "version": "0.1.13",
      "published_version": "0.1.13",
      "published_reason": null,
      "drift": false,
      "pending_publish": false,
      "pending_publish_reason": null,
      "source_commit": "6bdb6b1ede368a63e2494dd4cbc9ccdcd4624a57",
      "source_commit_reason": null,
      "tarball_sha256": null,
      "tarball_reason": "release-check.sh not run this generation; set CODERIFTS_TARBALL_SHA256_prove to the tarball sha256 to record it",
      "source": "capability-demo/package.json",
      "bucket": "derived"
    }
  },
  "verify_core": {
    "receipt_verifier": {
      "id": "receipt-verifier",
      "sha256": "52d7c37611f9eecc862e3678d1ffcb4fd860ea4c5faf9a9df6d6d5b290bd8197",
      "path": "receipt-verifier/verify.js",
      "reason": null
    },
    "python_verifier": {
      "id": "python-verifier",
      "sha256": "cf097e5c8bc64c066b34e7087d5b9edf48756f06acd9d700ff9ebf454215ceef",
      "path": "coderifts-python-verifier/coderifts_verifier/_verify.py",
      "reason": null
    },
    "contract_gate": {
      "id": "contract-gate",
      "sha256": "52d7c37611f9eecc862e3678d1ffcb4fd860ea4c5faf9a9df6d6d5b290bd8197",
      "path": "coderifts-contract-gate/src/verify.js",
      "reason": null
    },
    "gateway_verifier": {
      "id": "gateway-verifier",
      "sha256": "52d7c37611f9eecc862e3678d1ffcb4fd860ea4c5faf9a9df6d6d5b290bd8197",
      "path": "coderifts-gateway-verifier/src/verify.js",
      "reason": null
    },
    "k8s_admission": {
      "id": "k8s-admission",
      "sha256": "52d7c37611f9eecc862e3678d1ffcb4fd860ea4c5faf9a9df6d6d5b290bd8197",
      "path": "coderifts-k8s-admission/src/verify.js",
      "reason": null
    },
    "agent_guard_fixture": {
      "id": "agent-guard-fixture",
      "sha256": "363e52c72ec4b913e1f3edc8e2029848feaeacb1efa6c07960fe5e5f195c23b3",
      "path": "coderifts-agent-guard/test/fixtures/reference-core/verify.js",
      "reason": null
    }
  },
  "signed_release": {
    "tag": "v1.0.1",
    "tag_object": "06dd74f36f60e0b4d22dd4667732fe0a27575287",
    "peeled_commit": "51a8224439959a5b46c0b09e9a2cd67117f05d56",
    "signer": "zsobpeter@gmail.com",
    "fingerprint": "SHA256:7yRXTm9zKGicfFpzL+7lpwFoPaoSwxAJlabB3jwxw2Y",
    "verified": true,
    "verify_command": "git -C <receipt-verifier checkout> tag -v v1.0.1",
    "reason": null
  },
  "conformance": {
    "profiles": [
      {
        "id": "DECISION_LOGIC",
        "status": "COVERED",
        "title": "Verdict invariants",
        "runnable": 15,
        "vectors": 15
      },
      {
        "id": "RECEIPT_CRYPTO",
        "status": "COVERED",
        "title": "Signature and binding",
        "runnable": 16,
        "vectors": 16
      },
      {
        "id": "GUARDED_TOOL_TABLE",
        "status": "COVERED",
        "title": "The tools handed to the guard",
        "runnable": 6,
        "vectors": 6
      },
      {
        "id": "CREDENTIAL_BOUNDARY",
        "status": "COVERED",
        "title": "The raw host cannot write",
        "runnable": 4,
        "vectors": 4
      },
      {
        "id": "ATOMIC_COMMIT",
        "status": "COVERED",
        "title": "Nonce + CAS + attestation as one transaction",
        "runnable": 6,
        "vectors": 6
      },
      {
        "id": "PROVIDER_ENFORCED",
        "status": "COVERED",
        "title": "Merge or deploy refused at the provider",
        "runnable": 7,
        "vectors": 7
      },
      {
        "id": "END_TO_END",
        "status": "COVERED",
        "title": "Authorization through to a governed target state",
        "runnable": 2,
        "vectors": 2
      }
    ],
    "reason": null,
    "source": "coderifts-conformance/bin/coderifts-conformance.js"
  },
  "grant_version": {
    "effective_default": "v2",
    "changes_at": "2026-09-18",
    "source": "src/grant-version-default.js",
    "schema": "schemas/execution-grant-request.v2.producer.json",
    "bucket": "derived"
  },
  "surface": {
    "tools_sha256": "sha256:7d6fe4a0d5ef31a4cec82aaa0762c4434a246899233ff13321fe08b5cf8475d2",
    "tool_count": 3,
    "source_ref": "https://raw.githubusercontent.com/coderifts/api-governance/surface-7d6fe4a0/tools.wire.v1.json",
    "source_ref_commit": "d68d5c9d87d39fc8670c6fb6c1c702b4ad5f67bb",
    "source": "src/generated/surface-anchor.json",
    "bucket": "derived"
  },
  "test_count": {
    "test_count": 8360,
    "pass_count": 8359,
    "source": "src/generated/test-count.json",
    "measurement_commit": "45bb973894b0ffa96ceef66a7911fcac521567b5",
    "homepage": {
      "test_count": null,
      "reason": "generated test-count markers missing on website HEAD:index.html",
      "source": "HEAD:index.html"
    },
    "homepage_matches": true,
    "bucket": "derived"
  },
  "platforms": {
    "derivation": [
      "github",
      "gitlab",
      "bitbucket"
    ],
    "source": "src/scm/platforms.js PLATFORMS",
    "bucket": "derived",
    "note": "GitHub App Compare, or GitLab/Bitbucket Compare with per-request X-Coderifts-Scm-Token (never stored)."
  },
  "enforcement": {
    "claude_pretooluse": {
      "gates": "Contract-touching Write/Edit/MultiEdit at tool-call time",
      "default": "PREVENTS",
      "default_detail": "exit 2; fail-closed / enforce_indeterminate when governance cannot run",
      "opt_out": "CODERIFTS_ADVISORY=1",
      "source": "packages/cli/src/commands/claude-hook.js",
      "bucket": "derived"
    },
    "deploy_gate": {
      "gates": "Deploying an artifact whose receipt is stale/mismatched/unverified",
      "default": "PREVENTS",
      "default_detail": "fail-closed since CLI 4.3.0; verifies the signed receipt since 4.4.0; exit 1 on deny",
      "opt_out": "CODERIFTS_DEPLOY_ADVISORY=1 (or CODERIFTS_ADVISORY=1) → advisory, exit 0",
      "enforce_flag": "--enforce / CODERIFTS_DEPLOY_ENFORCE attests ENFORCING (exit already fail-closed)",
      "source": "packages/cli/src/commands/deploy-gate.js isDeployAdvisory({})",
      "bucket": "derived"
    },
    "github_app_merge_gate": {
      "gates": "PR contract check posted by the GitHub App",
      "check_name": "CodeRifts / contract-gate",
      "default": "REPORTS",
      "default_detail": "phase-1 conclusion clamped to neutral; MERGEGATE_ENFORCE default false",
      "opt_in": "MERGEGATE_ENFORCE=true → conclusion may be failure",
      "mergegate_enforce_default": false,
      "source": "src/mergegate/webhook-integration.js",
      "bucket": "derived"
    },
    "contract_gate_action": {
      "gates": "coderifts/contract-gate GitHub Action check (same name)",
      "check_name": "CodeRifts / contract-gate",
      "default": "REPORTS",
      "default_detail": "posts a real check conclusion; merge is not blocked until the check is required",
      "opt_in": "required status check bound to this Action (not name-only) → PREVENTS merge",
      "source": "packages/cli/src/contract-gate-workflow.js + coderifts-contract-gate",
      "bucket": "derived"
    },
    "publish_gate": {
      "gates": "npm prepublishOnly / coderifts publish-gate",
      "default": "PREVENTS",
      "default_detail": "exit 1 on BLOCK/STOP or resolver error",
      "source": "packages/cli/src/commands/publish-gate.js",
      "bucket": "derived"
    },
    "git_pre_push": {
      "gates": "Pushing spec changes without authorization",
      "default": "PREVENTS",
      "default_detail": "BLOCK/STOP → exit 1 when the hook is installed",
      "source": "packages/cli/src/commands/hook.js",
      "bucket": "derived"
    }
  },
  "prose": [
    {
      "fact": "Prevention holds inside the wired boundary — a host that bypasses the guarded table, uninstalls the hook, or merges on a repo without the required check is outside it.",
      "bucket": "prose",
      "review_date": "2026-08-25",
      "why": "product honesty line, not a code constant"
    },
    {
      "fact": "MCP analyze is informational (not permission); authorize may mint a receipt. The three canonical tools do not themselves prevent a call.",
      "bucket": "prose",
      "review_date": "2026-08-25",
      "why": "protocol meaning; the schemas encode it but the “does not prevent by itself” sentence is a product reading"
    }
  ]
}
