CatalogReview
A verified catalog as an operator sees it, without addresses or credentials.
Publisher that signed the catalog.
Catalog revision.
Catalog creation as a Unix timestamp.
Catalog expiry as a Unix timestamp.
Digest of the catalog document as fetched and retained.
entries object[]required
Listed releases.
Bundle identity the release belongs to.
Bundle version the release carries.
title object
Display title, if any.
- string
- null
Publisher that signed the release.
Publisher release sequence.
Digest of the signed claims, as inspection reviews them.
runtime_platform object
Exact artifact family of a runtime-bearing release; None for a plain one.
- string
- null
Digest of the executable artifact.
Signed artifact size in bytes.
Everything an install transfers: the artifact plus, for a runtime-bearing release, every wheel it lists.
Operating systems supported.
Skulk build the release binds to.
Signed permission summaries.
Qualified capability ids.
Titles of declared surfaces.
Whether durable operations are declared.
Steward exposure risk classes: observation, billable, effect.
Release expiry as a Unix timestamp.
Whether this host's Skulk build and platform match the release.
{
"publisher": "string",
"revision": 0,
"created_at": 0,
"expires_at": 0,
"catalog_sha256": "string",
"entries": [
{
"bundle_id": "string",
"bundle_version": "string",
"title": "string",
"publisher": "string",
"sequence": 0,
"release_digest": "string",
"runtime_platform": "string",
"artifact_sha256": "string",
"artifact_bytes": 0,
"transfer_bytes": 0,
"platforms": [
"string"
],
"skulk_build_sha256": "string",
"permissions": [
"string"
],
"descriptors": [
"string"
],
"surfaces": [
"string"
],
"operations": true,
"steward_risks": [
"string"
],
"expires_at": 0,
"matches_host": true
}
]
}