Skip to content

feat: require protected Host capability receipts - #60

Closed
fearclear wants to merge 2 commits into
mainfrom
feat/plugin-v8-architecture
Closed

feat: require protected Host capability receipts#60
fearclear wants to merge 2 commits into
mainfrom
feat/plugin-v8-architecture

Conversation

@fearclear

Copy link
Copy Markdown
Contributor

Summary:

  • add append-only Host capability policy v2 and protected human-decision receipt workflow
  • bind approvals to exact accepted Plugin API ids and contract digests, strict runtime conformance, npm bytes, Host commit, immutable Release, and builder attestation
  • update authoring docs and Skill so Plugins must submit Host requests and cannot edit Host implementation or generated Catalogs

Safety:

  • receipt consumers reject empty or legacy Catalogs, missing APIs, changed contract digests, forged conformance, bot or self approval, and mutable evidence
  • Multi Angle, Panorama Viewer, and Relight Studio remain publication-blocked until real external evidence exists
  • no target Plugin source was changed

Verification:

  • 119 tooling tests
  • repository validation with five expected fail-closed blockers
  • generated Skill API reference check
  • workflow YAML parsing and diff check

Rollout:

  • current vendored Catalog remains wire-schema/2 and SDK provenance is not yet published, so this PR intentionally does not remove the three blockers.

@fearclear

Copy link
Copy Markdown
Contributor Author

Replaced by #61, rebuilt from the latest main to avoid conflicts caused by the previously squash-merged branch history. The governance change itself is unchanged and revalidated.

@fearclear fearclear closed this Jul 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant