CatalogEntryReview
One listed release as an operator sees it: consent facts, no addresses.
Bundle identity the release belongs to.
Bundle version the release carries.
title object
Display title, if any.
- string
- null
Publisher that signed the release.
Publisher release sequence.
Digest of the signed claims, as inspection reviews them.
runtime_platform object
Exact artifact family of a runtime-bearing release; None for a plain one.
- string
- null
Digest of the executable artifact.
Signed artifact size in bytes.
Everything an install transfers: the artifact plus, for a runtime-bearing release, every wheel it lists.
Operating systems supported.
Skulk build the release binds to.
Signed permission summaries.
Qualified capability ids.
Titles of declared surfaces.
Whether durable operations are declared.
Steward exposure risk classes: observation, billable, effect.
Release expiry as a Unix timestamp.
Whether this host's Skulk build and platform match the release.
{
"bundle_id": "string",
"bundle_version": "string",
"title": "string",
"publisher": "string",
"sequence": 0,
"release_digest": "string",
"runtime_platform": "string",
"artifact_sha256": "string",
"artifact_bytes": 0,
"transfer_bytes": 0,
"platforms": [
"string"
],
"skulk_build_sha256": "string",
"permissions": [
"string"
],
"descriptors": [
"string"
],
"surfaces": [
"string"
],
"operations": true,
"steward_risks": [
"string"
],
"expires_at": 0,
"matches_host": true
}