activev0.3.0Catalog reviewed 2026-09-23

APTlantis Release Hashing Standard

Records release artifact hashes, distribution, and provenance authority.

Applies to: Published software artifacts such as installers, portable binaries, release archives and dataset packages.

Source maturity: candidate

Explanation reviewed 2026-10-01. Catalog identity and source review have separate dates.

Read public Markdown

Purpose and applicability

A release filename does not identify exact bytes. ARHS publishes a hash manifest tied to the final artifact and records the distribution/provenance boundary.

Published software artifacts such as installers, portable binaries, release archives and dataset packages.

How it works

Hash the final packaged artifact using SHA256, BLAKE3-256 and KT128. Name filename, version, location and size; record tool/command and distribution/signing authority. Publish the hash manifest beside the artifact so consumers can recompute and compare.

Outputs are the release hash manifest and verification record. SHA256 and BLAKE3-256 use lowercase hexadecimal in current records; KT128 means a 128-byte KangarooTwelve XOF digest encoded as base64.

In practice

The annotated record uses conspicuous placeholders rather than the example’s fabricated hashes and pass label. A matching digest checks byte integrity against a reference; it does not authenticate the reference’s publisher.

Annotated release-hash recordillustrative · teaching example, not a verification result

Illustrative incomplete record; placeholders fail actual release requirements.

Source: ARHS/ReleaseHashRecord.schema.toml
[release]
name = "ExampleTool"
version = "0.1.0"
artifact = "ExampleTool-0.1.0.zip"
path = "releases/ExampleTool-0.1.0.zip"
size_bytes = 0 # placeholder; measure final bytes
distribution = "not published"
signing = "not established"

[[hash]]
algorithm = "SHA256"
value = "COMPUTE_FROM_FINAL_ARTIFACT"
[[hash]]
algorithm = "BLAKE3-256"
value = "COMPUTE_32_BYTES_LOWERCASE_HEX"
[[hash]]
algorithm = "KT128"
value = "COMPUTE_128_BYTES_BASE64"
Inspect Annotated release-hash record

Adopt one part

Start with a bounded surface or record. Complete the relevant adopter checks before extending the claim.

  1. Choose the final release file and record exact filename, version and size.
  2. Generate all required hashes with a documented tool; retain the command and publish the manifest with the same artifact.
  3. Recompute hashes and record results; separately identify distribution and signing/provenance authority.

Sources and limits

No artifact hashes were computed here. ARHS does not sign packages. Platform signing or ecosystem provenance is separate from AAMHS archive signatures, and a sample record is not release verification.

These are reviewed public explanations, not the normative specifications. Suite references are relative to the canonical collection; site/ references identify committed website sources and webserver/ references identify serving configuration. Illustrative examples demonstrate record shape; they do not establish compliance. Suite checks and adopter validation are separate.

  • ARHS/ARHS.manifest.toml
  • ARHS/Adoption-Guide.md
  • ARHS/Validation-Checklist.md
  • ARHS/APTlantis Release Hashing Standard.md
  • ARHS/examples/Example-Release-Hash-Record.md
  • ARHS/ReleaseHashRecord.schema.toml
Reviewed manifest facts