Overview
dsh-proof
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- **Deny list must match the deployment's tools** — `tools.restrict` fails loud on unknown names, so a mismatched default blocks verifier startup. The exact mutating-tool set is deployment-specific and is resolved at first install. - **No evidence normalization** — the verifier gathers evidence itself; this plugin does not re-implement diff/test/typecheck/lint. A deployment wanting specific evidence channels should extend `verifierPrompt`. - **Best-effort spawn** — a provider that is absent or rejects the request degrades to a no-op (logged), rather than failing the user's turn.
