Qeravio
Qeravio package trust

Every shipped byte has a record. Publisher signing does not exist yet.

This record binds the current Codex and Claude package to exact archives, file hashes, a CycloneDX inventory, build provenance, licenses and a point-in-time dependency review. It also shows the evidence Qeravio still cannot claim.

2pinned release archives
60licensed file records
0bundled third-party runtime dependencies
1declared remote service dependency
Claim boundary

A checksum detects changed bytes. It does not prove who published them.

The current record is reproducible and internally verified, but it is not cryptographically signed, it is not tied to a verified marketplace publisher account, and no independent clean-room rebuild has been completed.

01 / Artifacts

The release record binds both downloadable archives.

Compare both byte count and the complete SHA-256 value before installing.

plugin-archiveHash matched

qeravio-ai-companion-3.1.0.zip

34,513 bytes

fd1b3b9f3a08…086190ff18bc
marketplace-bundleHash matched

qeravio-marketplace-3.1.0.zip

35,778 bytes

c5b8a8f93d66…7a995713e487
02 / Inventory

Files, dependencies and licenses stay separate.

  1. Archive inventory29 files in the plugin archiveEvery archive path, byte count and SHA-256 value is recorded.
  2. CycloneDXComplete file-level inventory for both archivesNo third-party runtime component is bundled in this package.
  3. LicenseRef-Qeravio-Proprietary-2026A license is assigned to every bundled file recordThe package is proprietary and governed by the published Qeravio terms.
  4. Point-in-time reviewNo known high-severity production dependency findingThis result is tied to the recorded lockfile and must be repeated after changes.
03 / Provenance

The build trace says exactly what it does not know.

Source treeDigest recorded
SHA-256

1526b0e4a02a…be5f096b8e4e

LimitNo repository commit is claimed or verified.

BuilderReproducible
research/build_plugin_release.py

Sorted paths, fixed time and permissions

LimitAn independent clean-environment rebuild has not been run.

AttestationUnsigned
in-toto / SLSA

Inputs and outputs are bound in a standard structure

LimitThe provenance file can be checked for consistency, but it does not authenticate a publisher.

04 / Open gates

What still blocks a complete supply-chain claim.

  1. 01Protected publisher signing key and public verification path.
  2. 02Verified publisher account in an approved host marketplace.
  3. 03Independent rebuild in a clean environment with matching archive digests.
  4. 04A fresh dependency and license gate for every future release.
Inspect the evidence

Download the records separately from the archives you verify.