Record format

@flashyos/checkpoint

checkpoint/1 — an RFC 6962 Merkle tree head over the sealed claims a property publishes. A static file beside the fragments: no server, no collector, no uptime.

version 0.2.0 · audit of 2026-10-04 · source: flashyos/packages/checkpoint

npm i @flashyos/checkpoint

The format deliberately stops short of a transparency log: retained heads, served consistency proofs and witness cosigning are gated on real adoption, and the SPEC states the boundary so a reader cannot mistake a reproducible root for tamper-evidence.

Edge cases — each one paid for once

A head is unsigned on purpose

A signature over a root you computed, checked with a key you published, is ceremony without a property — what makes history provably append-only is a witness who is not you. A partial signature is a validation error, because presence-checking would read it as signed.

Only the past tense can be a leaf source

backlog/1 items decay and are never sealed, so they carry no digest to commit to. The first real emit produced 97 leaves, all shipped — the two-tenses rule, discovered rather than designed.

← Full catalog · The doctrine behind the tools · Adopt one