{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:09:49Z",
  "record_id": "VXI-EXT-SIGSTORE-03-v1",
  "record_kind": "external_reference",
  "title": "Sigstore: Verification expectations",
  "system": "Sigstore",
  "evidence_family": "software_supply_chain",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Is verifying an artifact signature sufficient for a Sigstore reliance decision?",
  "near_questions": [
    "What must a Sigstore verification check besides a signature?",
    "Why does expected signer identity matter?",
    "Can an agent accept a certificate from any issuer?",
    "What evidence shows that signing material matches an artifact?",
    "Does successful verification authorise execution?",
    "How should a receipt capture the verification policy?",
    "Can a caller's verified flag replace independent checks?",
    "What is missing when only a signature file is supplied?",
    "Which record separates valid signatures from expected identity?",
    "How should log inclusion evidence be treated?",
    "What context is needed for an artifact verification review?",
    "Does source authenticity imply safe behaviour?"
  ],
  "supported_claims": [
    {
      "claim": "The documented Sigstore verification flow checks the signature, expected identity, certificate trust and log inclusion evidence. Reliance also needs the buyer's expected artifact and use context.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "all trust checks satisfied by signature mathematics alone",
    "verification of an actual customer artifact",
    "permission to execute after verification"
  ],
  "public_summary": "The documented Sigstore verification flow checks the signature, expected identity, certificate trust and log inclusion evidence. Reliance also needs the buyer's expected artifact and use context.",
  "related_record_ids": [
    "VXI-EXT-SLSA-12-PROV-01-v1",
    "VXI-EXT-SLSA-12-TRACK-01-v1",
    "VXI-EXT-SLSA-12-03-v1",
    "VXI-EXT-SIGSTORE-01-v1",
    "VXI-EXT-SIGSTORE-02-v1",
    "VXI-EXT-SIGSTORE-BUNDLE-01-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "Sigstore documentation",
    "source_url": "https://docs.sigstore.dev/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SIGSTORE-03-v1",
    "candidate_record_sha256": "b7c5fd4ca8c7f241e1bb0a9721722d2370ede1f9a531507b2f4340cb1ae9eb27",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "The documented Sigstore verification flow checks the signature, expected identity, certificate trust and log inclusion evidence. Reliance also needs the buyer's expected artifact and use context.",
    "required_buyer_context": "Artifact digest, expected identity and issuer, trust material and verification outcome.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#sigstore-verification-expectations",
  "machine_readable_record": "/varexis-index/records/sigstore-verification-expectations.json"
}
