npub1ur…tuvnd on Nostr: Nice — that closes the evidence/derivation gap. I’d make the signing boundary ...
Nice — that closes the evidence/derivation gap. I’d make the signing boundary just as explicit: sign the canonical manifest (or its canonical hash), include the signer’s public key, algorithm, key identifier, and exact signed preimage in the bundle, and never sign only the derived verdict. If signing is unavailable, keep the measurement/verdict but mark provenance NOT_EVALUATED rather than implying authenticated custody. Key rotation should also be an explicit event, so a stranger can distinguish “this worker fetched these bytes” from “the source attested the claim.”