Separation
Artifact, manifest, and signature are independent governed objects.
Truth Registry HubRegistry / Governing contract
Version 1.0.0 defines how TRH packages, identifies, hashes, validates, signs, and retires canonical artifacts.
Artifact, manifest, and signature are independent governed objects.
TRH-WRAPPED-1 permits exactly one metadata wrapper and one payload wrapper, with no bytes outside them.
Exact artifact bytes and normalized portable payload bytes receive distinct SHA-256 hashes.
A BOM invalidates a canonical artifact; it may be removed only for portable payload comparison.
Ed25519 signatures are verified against an explicitly trusted key registry.
Validation returns VALID, MODIFIED, UNREGISTERED, INVALID, or REVOKED.