Record format
@flashyos/checkpoint
checkpoint/1 — an RFC 6962 Merkle tree head over the sealed claims a property publishes. A static file beside the fragments: no server, no collector, no uptime.
version 0.2.0 · audit of 2026-10-04 · source: flashyos/packages/checkpoint
npm i @flashyos/checkpointThe format deliberately stops short of a transparency log: retained heads, served consistency proofs and witness cosigning are gated on real adoption, and the SPEC states the boundary so a reader cannot mistake a reproducible root for tamper-evidence.
Edge cases — each one paid for once
A head is unsigned on purpose
A signature over a root you computed, checked with a key you published, is ceremony without a property — what makes history provably append-only is a witness who is not you. A partial signature is a validation error, because presence-checking would read it as signed.
Only the past tense can be a leaf source
backlog/1 items decay and are never sealed, so they carry no digest to commit to. The first real emit produced 97 leaves, all shipped — the two-tenses rule, discovered rather than designed.