APTlantis Release Hashing Standard
Records release artifact hashes, distribution, and provenance authority.
Applies to: Published software artifacts such as installers, portable binaries, release archives and dataset packages.
Explanation reviewed 2026-10-01. Catalog identity and source review have separate dates.
Read public MarkdownPurpose and applicability
A release filename does not identify exact bytes. ARHS publishes a hash manifest tied to the final artifact and records the distribution/provenance boundary.
Published software artifacts such as installers, portable binaries, release archives and dataset packages.
How it works
Hash the final packaged artifact using SHA256, BLAKE3-256 and KT128. Name filename, version, location and size; record tool/command and distribution/signing authority. Publish the hash manifest beside the artifact so consumers can recompute and compare.
Outputs are the release hash manifest and verification record. SHA256 and BLAKE3-256 use lowercase hexadecimal in current records; KT128 means a 128-byte KangarooTwelve XOF digest encoded as base64.
In practice
The annotated record uses conspicuous placeholders rather than the example’s fabricated hashes and pass label. A matching digest checks byte integrity against a reference; it does not authenticate the reference’s publisher.
Illustrative incomplete record; placeholders fail actual release requirements.
Source: ARHS/ReleaseHashRecord.schema.toml[release]
name = "ExampleTool"
version = "0.1.0"
artifact = "ExampleTool-0.1.0.zip"
path = "releases/ExampleTool-0.1.0.zip"
size_bytes = 0 # placeholder; measure final bytes
distribution = "not published"
signing = "not established"
[[hash]]
algorithm = "SHA256"
value = "COMPUTE_FROM_FINAL_ARTIFACT"
[[hash]]
algorithm = "BLAKE3-256"
value = "COMPUTE_32_BYTES_LOWERCASE_HEX"
[[hash]]
algorithm = "KT128"
value = "COMPUTE_128_BYTES_BASE64"Adopt one part
Start with a bounded surface or record. Complete the relevant adopter checks before extending the claim.
- Choose the final release file and record exact filename, version and size.
- Generate all required hashes with a documented tool; retain the command and publish the manifest with the same artifact.
- Recompute hashes and record results; separately identify distribution and signing/provenance authority.
Sources and limits
No artifact hashes were computed here. ARHS does not sign packages. Platform signing or ecosystem provenance is separate from AAMHS archive signatures, and a sample record is not release verification.
These are reviewed public explanations, not the normative specifications. Suite references are relative to the canonical collection; site/ references identify committed website sources and webserver/ references identify serving configuration. Illustrative examples demonstrate record shape; they do not establish compliance. Suite checks and adopter validation are separate.
ARHS/ARHS.manifest.tomlARHS/Adoption-Guide.mdARHS/Validation-Checklist.mdARHS/APTlantis Release Hashing Standard.mdARHS/examples/Example-Release-Hash-Record.mdARHS/ReleaseHashRecord.schema.toml