{
  "$comment": "Schema retrieval URLs and byte digests. V1 is served at its $id; v0 retains its legacy $id and is mirrored at url. Built from github.com/backbay-labs/hush; commit identifies the source.",
  "host": "https://hushspec.org/schemas/",
  "schemas": [
    {
      "file": "hushspec-assessment-context-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-assessment-context-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-assessment-context-experimental.v1.schema.json",
      "sha256": "0858c70711efa99361433404256cccad68669228e15d88c723b5ac060147997d",
      "title": "HushSpec assessment-context-experimental 0.1.0",
      "description": "Experimental offline assurance companion. Not a certification or a change to stable HushSpec evidence formats."
    },
    {
      "file": "hushspec-bundle.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-bundle.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-bundle.v0.schema.json",
      "sha256": "e3aca3f8a906f0aae6bf8cb76fa68721c9923b4f8a14527379e55df328677372",
      "title": "HushSpec Policy Bundle v0.1",
      "description": "A policy bundle (spec/hushspec-bundle.md): a DSSE envelope whose payload is an in-toto Statement v1 carrying the resolved policy, its extends chain, and the resolver that produced them. The root of this schema is the envelope; the base64 payload cannot be validated in place, so a verifier decodes it and validates the result against #/$defs/Statement."
    },
    {
      "file": "hushspec-bundle.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-bundle.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-bundle.v1.schema.json",
      "sha256": "4d562c5ed63d8b64bbf1b84db038a16d3d63e1ec851a9f20da0593cd384b0093",
      "title": "HushSpec Policy Bundle v0.1",
      "description": "A policy bundle (spec/hushspec-bundle.md): a DSSE envelope whose payload is an in-toto Statement v1 carrying the resolved policy, its extends chain, and the resolver that produced them. The root of this schema is the envelope; the base64 payload cannot be validated in place, so a verifier decodes it and validates the result against #/$defs/Statement."
    },
    {
      "file": "hushspec-conformance-execution-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-conformance-execution-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-conformance-execution-experimental.v1.schema.json",
      "sha256": "78dff3ee597d745329f917abcf0a1ddea7b14726ccd7d4ea80454b17d709aced",
      "title": "Experimental conformance execution record 0.1.0"
    },
    {
      "file": "hushspec-conformance-report.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-conformance-report.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-conformance-report.v0.schema.json",
      "sha256": "6aa04ed7ebc537ac0a02d0a92da2c5d8ee0cbc19904d327b535a6cecbe834da8",
      "title": "HushSpec Conformance Report v0",
      "description": "The machine-readable result of running the HushSpec conformance corpus against one implementation (core spec Section 8). A report names the implementation, pins the corpus by its manifest digest, states an outcome for each of the six conformance levels, and lists every vector it ran. It is the evidence behind a conformance statement (docs/src/reference/conformance-statement.md); a statement that cites a level MUST be backed by a report whose entry for that level is \"pass\"."
    },
    {
      "file": "hushspec-conformance-report.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-conformance-report.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-conformance-report.v1.schema.json",
      "sha256": "076c5c4dd3c63f63122f27d90f302f181a481df641c7db74bba1ecb0ec7cf17e",
      "title": "HushSpec Conformance Report v1",
      "description": "The machine-readable result of running the HushSpec conformance corpus against one implementation (core spec Section 8). A report names the implementation, pins the corpus by its manifest digest, states an outcome for each of the six conformance levels, and lists every vector it ran. It is the evidence behind a conformance statement (docs/src/reference/conformance-statement.md); a statement that cites a level MUST be backed by a report whose entry for that level is \"pass\"."
    },
    {
      "file": "hushspec-core.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-core.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-core.v0.schema.json",
      "sha256": "664df8ccd7b4127f9f56bc247c1d268ca745b9890e762fc57a97cb4481641574",
      "title": "HushSpec Core v0",
      "description": "Schema for HushSpec Core v0.x documents. Validates portable, engine-neutral AI agent security rules."
    },
    {
      "file": "hushspec-core.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-core.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-core.v1.schema.json",
      "sha256": "d24095809e5d0618798c0102ac9414bedfd40bfe8e320011dc10971a8b4358e2",
      "title": "HushSpec Core v1",
      "description": "Schema for HushSpec Core 1.x documents, which also accepts the frozen 0.x lineage (core spec 2.2). Validates portable, engine-neutral AI agent security rules."
    },
    {
      "file": "hushspec-detection.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-detection.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-detection.v0.schema.json",
      "sha256": "962d0f15b966155367f974eea71109c8b9ff2c406fe5e34ce6dde672a143190a",
      "title": "HushSpec Detection Extension v0",
      "description": "Schema for the HushSpec Detection extension. Declares thresholds and configuration for content analysis guards."
    },
    {
      "file": "hushspec-detection.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-detection.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-detection.v1.schema.json",
      "sha256": "38e1c320dee06b3b9d5f7b7ab5ef47148e04219a5209e305e99bd4a184215d5f",
      "title": "HushSpec Detection Extension v1",
      "description": "Schema for the HushSpec Detection extension. Declares thresholds and configuration for content analysis guards."
    },
    {
      "file": "hushspec-engine-profile-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-engine-profile-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-engine-profile-experimental.v1.schema.json",
      "sha256": "55ca05db06b0e39711eed3b8c6ad66e1cf075c84feea2f61b2ade9f09526af42",
      "title": "Experimental external engine profile 0.1.0"
    },
    {
      "file": "hushspec-engine-request-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-engine-request-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-engine-request-experimental.v1.schema.json",
      "sha256": "3b610464058323f1d6fa857c049f1c800554fa53be5bd03ebd5271ff3133efca",
      "title": "Experimental external engine request 0.1.0"
    },
    {
      "file": "hushspec-engine-response-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-engine-response-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-engine-response-experimental.v1.schema.json",
      "sha256": "4e61fb355e85de6b32c7cfddc36a9077d752b0b7bdfef7cc662b1b214a51449a",
      "title": "Experimental external engine response 0.1.0"
    },
    {
      "file": "hushspec-error-codes.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-error-codes.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-error-codes.v0.schema.json",
      "sha256": "6ec914d5deae5ff1e3cbbbea841d7f21c5aa17e8acc092072b4e92a188503413",
      "title": "HushSpec Error Code Registry v0",
      "description": "Schema for spec/registries/error-codes.yaml, the registry of stable identifiers an implementation reports when it refuses a HushSpec document, and for the <name>.expect.yaml sidecars that name the code an invalid/ vector must be rejected with."
    },
    {
      "file": "hushspec-error-codes.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-error-codes.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-error-codes.v1.schema.json",
      "sha256": "f85806ab8a0aad27e6383c9b919c3b1f01f76427f98df5f66417bef2beac2000",
      "title": "HushSpec Error Code Registry v1",
      "description": "Schema for spec/registries/error-codes.yaml, the registry of stable identifiers an implementation reports when it refuses a HushSpec document, and for the <name>.expect.yaml sidecars that name the code an invalid/ vector must be rejected with."
    },
    {
      "file": "hushspec-evaluator-test.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-evaluator-test.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-evaluator-test.v0.schema.json",
      "sha256": "07b6ec578fdfeaa748db5bd2e111d3bfdc245a228ef299ff2e5af9067dd5103c",
      "title": "HushSpec Evaluator Fixture v0",
      "description": "Schema for versioned evaluator fixtures used by the HushSpec reference evaluator and conformance testkit."
    },
    {
      "file": "hushspec-evaluator-test.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-evaluator-test.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-evaluator-test.v1.schema.json",
      "sha256": "1a142d4b7be3940ee00ec994b6785cfcb86a19322f3088604c1f710cc8a93ec4",
      "title": "HushSpec Evaluator Fixture v1",
      "description": "Schema for versioned evaluator fixtures used by the HushSpec reference evaluator and conformance testkit."
    },
    {
      "file": "hushspec-evidence-inventory-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-evidence-inventory-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-evidence-inventory-experimental.v1.schema.json",
      "sha256": "b46a84d5f07cd7f838a069827daa64a4f7c8482670f047dcbcd857b2471acff4",
      "title": "HushSpec evidence-inventory-experimental 0.1.0",
      "description": "Experimental offline assurance companion. Not a certification or a change to stable HushSpec evidence formats."
    },
    {
      "file": "hushspec-evidence-profile-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-evidence-profile-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-evidence-profile-experimental.v1.schema.json",
      "sha256": "beee35d1e146c5030d59ba59b135adb4b100e5a3d5af0ba9cc757480d80a0337",
      "title": "HushSpec evidence-profile-experimental 0.1.0",
      "description": "Experimental offline assurance companion. Not a certification or a change to stable HushSpec evidence formats."
    },
    {
      "file": "hushspec-evidence-verification-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-evidence-verification-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-evidence-verification-experimental.v1.schema.json",
      "sha256": "b00e37f7136d054552b75a3069912887bf7d121cc850822286481d14ba6f3187",
      "title": "HushSpec evidence-verification-experimental 0.1.0",
      "description": "Experimental offline assurance companion. Not a certification or a change to stable HushSpec evidence formats."
    },
    {
      "file": "hushspec-framework-registry.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-framework-registry.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-framework-registry.v0.schema.json",
      "sha256": "da96f8c91f7271255d6cfca94a206a7dfe88cd6fbe5c25e94039498901ccaf20",
      "title": "HushSpec Framework Registry v0",
      "description": "Schema for spec/registries/frameworks.yaml, the registry of compliance frameworks that metadata.controls[].framework may name."
    },
    {
      "file": "hushspec-framework-registry.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-framework-registry.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-framework-registry.v1.schema.json",
      "sha256": "004a4175df9a2da11f1fdfa00e5fa89c29763757d7d4338b4a426dbb0d2ea52c",
      "title": "HushSpec Framework Registry v1",
      "description": "Schema for spec/registries/frameworks.yaml, the registry of compliance frameworks that metadata.controls[].framework may name."
    },
    {
      "file": "hushspec-hash-vector.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-hash-vector.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-hash-vector.v0.schema.json",
      "sha256": "b3e019e6a2add8e9d0a4ec734f7bc4b470114ef5e731a2cfb3a03b57ed072171",
      "title": "HushSpec Canonical Form Test Vector v0",
      "description": "A test vector for spec/hushspec-canonical.md. Each vector pairs a resolved HushSpec document with the exact canonical JSON serialization and content hash a conformant implementation MUST produce for it. Vectors live under fixtures/core/hash/ and are generated by scripts/canonical_json.py."
    },
    {
      "file": "hushspec-hash-vector.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-hash-vector.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-hash-vector.v1.schema.json",
      "sha256": "b047eaae67489f132b70d1ccd6dedd9004f749f81e1927e88d06dee01d466322",
      "title": "HushSpec Canonical Form Test Vector v1",
      "description": "A test vector for spec/hushspec-canonical.md. Each vector pairs a resolved HushSpec document with the exact canonical JSON serialization and content hash a conformant implementation MUST produce for it. Vectors live under fixtures/core/hash/ and are generated by scripts/canonical_json.py."
    },
    {
      "file": "hushspec-invocation-journal-experimental.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-invocation-journal-experimental.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-invocation-journal-experimental.v1.schema.json",
      "sha256": "9aa08b06b714e3eb00037aec0bba56083a86df65a57f3bbdcc8404881c9b623c",
      "title": "Experimental trusted invocation evidence 0.1.0",
      "description": "A separate signed invocation entry or closing checkpoint. Structural validation alone is not verification: consumers must validate embedded policies and 0.2 receipts, signatures, sequence, immutable bindings and state transitions. Missing terminal evidence means unknown execution outcome."
    },
    {
      "file": "hushspec-keyring.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-keyring.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-keyring.v0.schema.json",
      "sha256": "9d568431bfea782f5eab21db2c86ed292b78b0f9310fab4d1e4b852348584ba9",
      "title": "HushSpec Trusted Keyring v0.2",
      "description": "The set of public keys a verifier trusts for policy signatures. Normative prose: spec/hushspec-signing.md section 5. A verifier MUST select the key whose key_id equals the envelope's key_id and MUST NOT fall back to any other key."
    },
    {
      "file": "hushspec-keyring.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-keyring.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-keyring.v1.schema.json",
      "sha256": "eb1d26fb4358039285405387f01e74b0906c47b591364c450bec3f15ce7221a4",
      "title": "HushSpec Trusted Keyring v0.2",
      "description": "The set of public keys a verifier trusts for policy signatures. Normative prose: spec/hushspec-signing.md section 5. A verifier MUST select the key whose key_id equals the envelope's key_id and MUST NOT fall back to any other key."
    },
    {
      "file": "hushspec-log-entry.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-log-entry.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-log-entry.v0.schema.json",
      "sha256": "ed5c0e22ef202cb957bd2f82c675f1ac6c701feb7d941f0986cf03923c4b767e",
      "title": "HushSpec Log Entry v0.1",
      "description": "One line of a hash-linked receipt log (spec/hushspec-log.md). Each entry wraps a decision receipt or a policy-in-effect event, names the previous entry's hash, carries its own hash over its canonical form, and may carry an Ed25519 signature over that hash. A verifier detects edited, deleted, inserted, or reordered lines from the entries alone."
    },
    {
      "file": "hushspec-log-entry.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-log-entry.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-log-entry.v1.schema.json",
      "sha256": "23237f5c55c0dc58faa6455ba0c77a3b4ab535b1c9c2549b655b8aa44ec6870b",
      "title": "HushSpec Log Entry v0.1",
      "description": "One line of a hash-linked receipt log (spec/hushspec-log.md). Each entry wraps a decision receipt or a policy-in-effect event, names the previous entry's hash, carries its own hash over its canonical form, and may carry an Ed25519 signature over that hash. A verifier detects edited, deleted, inserted, or reordered lines from the entries alone."
    },
    {
      "file": "hushspec-merge-vector.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-merge-vector.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-merge-vector.v0.schema.json",
      "sha256": "c179ca44a3a55fb643d4a43b8d273fb2a65e3804e95bbd4fc4e74870553fd92f",
      "title": "HushSpec Merge Vector v0",
      "description": "The shape of a merge vector directory under fixtures/ (core spec Section 4, Merge Semantics; Section 8 Level 2). Merge vectors are a directory convention rather than a single file, so this schema describes the *descriptor* a conformance runner builds for one directory -- which is what the four SDK runners already reconstruct from the filenames -- and, under $defs/FixtureManifest, the optional fixture.yaml that sits in the directory.\n\nDiscovery. A merge vector directory is any directory under fixtures/ that holds a base.yaml beside at least one child-<name>.yaml. Runners walk fixtures/<module>/merge/ and its subdirectories; a vector that needs its own base -- a digest pin names one exact document, so a pin-match and a pin-mismatch case cannot share one -- gets a subdirectory instead of colliding with the shared base.\n\nFiles. base.yaml is the parent document. child-<name>.yaml is the overlay; its merge_strategy selects the strategy under test. expected-<name>.yaml is the document the merge MUST produce, matched to its child by replacing the leading 'child-' with 'expected-'. Any other *.yaml in the directory (an intermediate hop of a multi-hop chain, say) is inert: runners only iterate the child-*.yaml files.\n\nComposition. A child whose extends carries a '#sha256:' pin is resolved (core Section 2.3) with a loader scoped to the vector directory, which also accepts the bare references 'base' and 'base.yaml'; the pin is then actually checked. Every other child is composed with a direct merge(base, child), which is what the vectors are testing.\n\nRefusal. A vector that must be refused rather than merged carries no expected-<name>.yaml and is marked instead. Only two markings are honoured by all four SDK runners, so only these two are normative: an 'expect-reject' file in the directory, or 'reject: true' in the directory's fixture.yaml. Both are directory-wide; a refusal case therefore lives in its own subdirectory with its own base.yaml. The per-child spellings some runners additionally accept (a '<stem>.expect-reject' marker, a 'reject' name list, per-child entries under 'cases') are tolerated aliases, not portable."
    },
    {
      "file": "hushspec-merge-vector.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-merge-vector.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-merge-vector.v1.schema.json",
      "sha256": "1c12263b97445b8b791528464017c3feeb0ce580724b8697fdea025286b863ea",
      "title": "HushSpec Merge Vector v1",
      "description": "The shape of a merge vector directory under fixtures/ (core spec Section 4, Merge Semantics; Section 8 Level 2). Merge vectors are a directory convention rather than a single file, so this schema describes the *descriptor* a conformance runner builds for one directory -- which is what the four SDK runners already reconstruct from the filenames -- and, under $defs/FixtureManifest, the optional fixture.yaml that sits in the directory.\n\nDiscovery. A merge vector directory is any directory under fixtures/ that holds a base.yaml beside at least one child-<name>.yaml. Runners walk fixtures/<module>/merge/ and its subdirectories; a vector that needs its own base -- a digest pin names one exact document, so a pin-match and a pin-mismatch case cannot share one -- gets a subdirectory instead of colliding with the shared base.\n\nFiles. base.yaml is the parent document. child-<name>.yaml is the overlay; its merge_strategy selects the strategy under test. expected-<name>.yaml is the document the merge MUST produce, matched to its child by replacing the leading 'child-' with 'expected-'. Any other *.yaml in the directory (an intermediate hop of a multi-hop chain, say) is inert: runners only iterate the child-*.yaml files.\n\nComposition. A child whose extends carries a '#sha256:' pin is resolved (core Section 2.3) with a loader scoped to the vector directory, which also accepts the bare references 'base' and 'base.yaml'; the pin is then actually checked. Every other child is composed with a direct merge(base, child), which is what the vectors are testing.\n\nRefusal. A vector that must be refused rather than merged carries no expected-<name>.yaml and is marked instead. Only two markings are honoured by all four SDK runners, so only these two are normative: an 'expect-reject' file in the directory, or 'reject: true' in the directory's fixture.yaml. Both are directory-wide; a refusal case therefore lives in its own subdirectory with its own base.yaml. The per-child spellings some runners additionally accept (a '<stem>.expect-reject' marker, a 'reject' name list, per-child entries under 'cases') are tolerated aliases, not portable."
    },
    {
      "file": "hushspec-origins.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-origins.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-origins.v0.schema.json",
      "sha256": "ab6797e3cfa7c1cc891b54df776f92698500811f366a50ad77170e68ee89c643",
      "title": "HushSpec Origins Extension v0",
      "description": "Schema for the HushSpec Origins extension. Declares origin-aware policy projection for multi-source agent workflows."
    },
    {
      "file": "hushspec-origins.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-origins.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-origins.v1.schema.json",
      "sha256": "fa87bda36d326495b8e0d17753edaf4b968eeba5aeb610041862fb5a90875c48",
      "title": "HushSpec Origins Extension v1",
      "description": "Schema for the HushSpec Origins extension. Declares origin-aware policy projection for multi-source agent workflows."
    },
    {
      "file": "hushspec-posture.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-posture.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-posture.v0.schema.json",
      "sha256": "3a884b3ce98ff168cacbbf3ed968034152d733800cc647fad2fded7074bdde83",
      "title": "HushSpec Posture Extension v0",
      "description": "Schema for the HushSpec Posture extension. Declares a state machine for capability and budget management."
    },
    {
      "file": "hushspec-posture.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-posture.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-posture.v1.schema.json",
      "sha256": "8a1c561f866ca00e7609fd9ce5761058d5726a03f86c3339603e0e3be761d276",
      "title": "HushSpec Posture Extension v1",
      "description": "Schema for the HushSpec Posture extension. Declares a state machine for capability and budget management."
    },
    {
      "file": "hushspec-receipt.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-receipt.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-receipt.v0.schema.json",
      "sha256": "28acbc5c8be87d5201c5c568f2e571f7a78ef822a09ec73d2465bd5c64e40c5b",
      "title": "HushSpec Decision Receipt v0.2",
      "description": "A self-contained, tamper-evident record of one HushSpec policy evaluation. Normative prose: spec/hushspec-receipt.md. A receipt identifies the resolved policy by content hash (spec/hushspec-canonical.md), the actor on whose behalf the action was evaluated, the action (never its content), the decision and why, the rule blocks and detectors that ran, and how the runtime applied the decision. Field order in this file is documentation order; receipts are hashed in canonical form (RFC 8785)."
    },
    {
      "file": "hushspec-receipt.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-receipt.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-receipt.v1.schema.json",
      "sha256": "cc81c5cea7e200547f8c2f9324de4b50e8e92e8ccef5132f57fef3cdb900dade",
      "title": "HushSpec Decision Receipt v0.2",
      "description": "A self-contained, tamper-evident record of one HushSpec policy evaluation. Normative prose: spec/hushspec-receipt.md. A receipt identifies the resolved policy by content hash (spec/hushspec-canonical.md), the actor on whose behalf the action was evaluated, the action (never its content), the decision and why, the rule blocks and detectors that ran, and how the runtime applied the decision. Field order in this file is documentation order; receipts are hashed in canonical form (RFC 8785)."
    },
    {
      "file": "hushspec-registry-action-types.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-action-types.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-action-types.v0.schema.json",
      "sha256": "c55c52dc6a8d1c3852b89c68c55a3cee8a3a90e950458d7536982d9b1b734b5c",
      "title": "HushSpec Action-Type Registry v0",
      "description": "Shape of spec/registries/action-types.yaml."
    },
    {
      "file": "hushspec-registry-capabilities.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-capabilities.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-capabilities.v0.schema.json",
      "sha256": "d33134024930e663d52fe0955a9442185dbbe76264a053a15ba8e52624c3486d",
      "title": "HushSpec Capability Registry v0",
      "description": "Shape of spec/registries/capabilities.yaml."
    },
    {
      "file": "hushspec-registry-condition-types.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-condition-types.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-condition-types.v0.schema.json",
      "sha256": "095b32eef42ba942f5c1a4694b5727d9fd4c2342d2f92e0d3a14a365c50be200",
      "title": "HushSpec Condition-Type Registry v0",
      "description": "Shape of spec/registries/condition-types.yaml."
    },
    {
      "file": "hushspec-registry-detectors.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-detectors.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-detectors.v0.schema.json",
      "sha256": "e484fde82a5da72bb1aecb32fc6b23bb8644b4707f04cf74fea466b19154c940",
      "title": "HushSpec Detector Registry v0",
      "description": "Shape of spec/registries/detectors.yaml."
    },
    {
      "file": "hushspec-registry-media-types.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-media-types.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-media-types.v0.schema.json",
      "sha256": "776628cef2ef0adb009a3533c8d1f5e8ada22352e7b82f343d7d25b5d29e35e5",
      "title": "HushSpec Media-Type Registry v0",
      "description": "Shape of spec/registries/media-types.yaml."
    },
    {
      "file": "hushspec-registry-rule-blocks.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-rule-blocks.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-rule-blocks.v0.schema.json",
      "sha256": "f7d473d326c1cee4dace9f749637d546f6bd89424270d0b21fd2a87c8a18439b",
      "title": "HushSpec Rule-Block Registry v0",
      "description": "Shape of spec/registries/rule-blocks.yaml."
    },
    {
      "file": "hushspec-registry-rule-paths.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-registry-rule-paths.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-registry-rule-paths.v0.schema.json",
      "sha256": "539fdf1ded71194b3c33ae872889b205d70ebc6c7043796437fe836e8b990a22",
      "title": "HushSpec Rule-Path Registry v0",
      "description": "Shape of spec/registries/rule-paths.yaml."
    },
    {
      "file": "hushspec-report.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-report.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-report.v0.schema.json",
      "sha256": "adb729f6637eae1d51ff32457af4d92e2dad096f12f443992caa82fe63f545d6",
      "title": "HushSpec Evidence Report v0.1",
      "description": "An aggregation over decision receipts and policy-in-effect events for one window (`h2h report --format json`). A report is derived evidence: every number is counted from recorded receipts (spec/hushspec-receipt.md) and never re-evaluated, so a report cannot disagree with the receipts it summarizes. When the inputs were hash-linked logs (spec/hushspec-log.md), `chain_verified` says whether the chain verified; a report over a broken chain is only produced when the operator asked for one, and is stamped false."
    },
    {
      "file": "hushspec-report.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-report.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-report.v1.schema.json",
      "sha256": "a11222dc02cfc09975ed08121a1c4b1ca711e2aeafc6061e88acb5e74723fa3c",
      "title": "HushSpec Evidence Report v0.1",
      "description": "An aggregation over decision receipts and policy-in-effect events for one window (`h2h report --format json`). A report is derived evidence: every number is counted from recorded receipts (spec/hushspec-receipt.md) and never re-evaluated, so a report cannot disagree with the receipts it summarizes. When the inputs were hash-linked logs (spec/hushspec-log.md), `chain_verified` says whether the chain verified; a report over a broken chain is only produced when the operator asked for one, and is stamped false."
    },
    {
      "file": "hushspec-signature.v0.schema.json",
      "$id": "https://hushspec.dev/schemas/hushspec-signature.v0.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-signature.v0.schema.json",
      "sha256": "cc092946b1eb67a3efe1d85b79d60a030ba8760c12606c1217602bab9f51f32f",
      "title": "HushSpec Policy Signature Envelope v0.2",
      "description": "A detached Ed25519 signature over the canonical form of a resolved HushSpec policy. Stored as a .sig JSON file next to the policy. Normative prose: spec/hushspec-signing.md. The signature covers the RFC 8785 canonical serialization of this object with the `signature` member removed."
    },
    {
      "file": "hushspec-signature.v1.schema.json",
      "$id": "https://hushspec.org/schemas/hushspec-signature.v1.schema.json",
      "url": "https://hushspec.org/schemas/hushspec-signature.v1.schema.json",
      "sha256": "eb2c9fd7e881ec3250d4a49f09d1af7127f1ab6990dfde9ebf056781e09299d9",
      "title": "HushSpec Policy Signature Envelope v0.2",
      "description": "A detached Ed25519 signature over the canonical form of a resolved HushSpec policy. Stored as a .sig JSON file next to the policy. Normative prose: spec/hushspec-signing.md. The signature covers the RFC 8785 canonical serialization of this object with the `signature` member removed."
    }
  ],
  "registries": [
    {
      "file": "action-types.yaml",
      "url": "https://hushspec.org/registries/action-types.yaml",
      "sha256": "857eb82e043c40353fab80cb59e36c0ba1b20dff5a46b37106c52f4af9154e76"
    },
    {
      "file": "capabilities.yaml",
      "url": "https://hushspec.org/registries/capabilities.yaml",
      "sha256": "706a59fca9fabb4fbc2d8f655cb6de011cd609e101d26fedf134913fc7a83d84"
    },
    {
      "file": "condition-types.yaml",
      "url": "https://hushspec.org/registries/condition-types.yaml",
      "sha256": "0d2ba584e8211ee1c5f60da73a2f069168c8fb750c10c2a6bf3706af1b0553c4"
    },
    {
      "file": "detectors.yaml",
      "url": "https://hushspec.org/registries/detectors.yaml",
      "sha256": "0817ec9224f51841ac8456ab1ea589ed8c4e31d13da770daf0a7dfe8d43f4df7"
    },
    {
      "file": "error-codes.yaml",
      "url": "https://hushspec.org/registries/error-codes.yaml",
      "sha256": "07f946cd34a3c44d34146088c12789630a3060d746df43bb8e479b90385c1098"
    },
    {
      "file": "frameworks.yaml",
      "url": "https://hushspec.org/registries/frameworks.yaml",
      "sha256": "0559b00da6ebff82946e61451ef9ec6c9914a9485096c0f3b69110a4546d649a"
    },
    {
      "file": "media-types.yaml",
      "url": "https://hushspec.org/registries/media-types.yaml",
      "sha256": "ec004494aae9fe9ad04f1b4acb8230b48abd260fa73b89688d0c0a950e17e777"
    },
    {
      "file": "rule-blocks.yaml",
      "url": "https://hushspec.org/registries/rule-blocks.yaml",
      "sha256": "c3cc005f732def7f7a89d3d8a02a7e0822c40fc9adb9135adabd05e2273e44b7"
    },
    {
      "file": "rule-paths.yaml",
      "url": "https://hushspec.org/registries/rule-paths.yaml",
      "sha256": "190f64e4b61516aee91d7a744c76b18b767441ffa9cf7d075b7fcc0750798629"
    }
  ],
  "commit": "e771ec647b7f26a0a09ff852886eb8a91093bc58"
}
