Skip to main content

CatalogReview

A verified catalog as an operator sees it, without addresses or credentials.

publisherPublisher (string)required

Publisher that signed the catalog.

revisionRevision (integer)required

Catalog revision.

created_atCreated At (integer)required

Catalog creation as a Unix timestamp.

expires_atExpires At (integer)required

Catalog expiry as a Unix timestamp.

catalog_sha256Catalog Sha256 (string)required

Digest of the catalog document as fetched and retained.

entries object[]required

Listed releases.

  • Array [
  • bundle_idBundle Id (string)required

    Bundle identity the release belongs to.

    bundle_versionBundle Version (string)required

    Bundle version the release carries.

    title object

    Display title, if any.

    anyOf
    string
    publisherPublisher (string)required

    Publisher that signed the release.

    sequenceSequence (integer)required

    Publisher release sequence.

    release_digestRelease Digest (string)required

    Digest of the signed claims, as inspection reviews them.

    runtime_platform object

    Exact artifact family of a runtime-bearing release; None for a plain one.

    anyOf
    string
    artifact_sha256Artifact Sha256 (string)required

    Digest of the executable artifact.

    artifact_bytesArtifact Bytes (integer)required

    Signed artifact size in bytes.

    transfer_bytesTransfer Bytes (integer)required

    Everything an install transfers: the artifact plus, for a runtime-bearing release, every wheel it lists.

    platformsstring[]required

    Operating systems supported.

    skulk_build_sha256Skulk Build Sha256 (string)required

    Skulk build the release binds to.

    permissionsstring[]required

    Signed permission summaries.

    descriptorsstring[]required

    Qualified capability ids.

    surfacesstring[]required

    Titles of declared surfaces.

    operationsOperations (boolean)required

    Whether durable operations are declared.

    steward_risksstring[]required

    Steward exposure risk classes: observation, billable, effect.

    expires_atExpires At (integer)required

    Release expiry as a Unix timestamp.

    matches_hostMatches Host (boolean)required

    Whether this host's Skulk build and platform match the release.

  • ]
  • CatalogReview
    {
    "publisher": "string",
    "revision": 0,
    "created_at": 0,
    "expires_at": 0,
    "catalog_sha256": "string",
    "entries": [
    {
    "bundle_id": "string",
    "bundle_version": "string",
    "title": "string",
    "publisher": "string",
    "sequence": 0,
    "release_digest": "string",
    "runtime_platform": "string",
    "artifact_sha256": "string",
    "artifact_bytes": 0,
    "transfer_bytes": 0,
    "platforms": [
    "string"
    ],
    "skulk_build_sha256": "string",
    "permissions": [
    "string"
    ],
    "descriptors": [
    "string"
    ],
    "surfaces": [
    "string"
    ],
    "operations": true,
    "steward_risks": [
    "string"
    ],
    "expires_at": 0,
    "matches_host": true
    }
    ]
    }