The reviewed BOM is the sole build/publication input. It pins the repository commit, upstream source commit, release tag, sequence, timestamp, toolchain, recipe, complete archive allowlist, entrypoints, SPDX licence files, exact SHA-256, and exact byte size. Branch names, latest URLs, workflow source edits, and discovered files are forbidden inputs.
The production job MUST execute these gates in order and stop on the first failure:
previous.sequence + 1.scripts/inspect_archives.py; verify allowlisted paths, no traversal/symlinks/encryption/collisions/bombs, x64 PE entrypoints, licence files, SHA-256, and byte size.--version, startup, clean shutdown, CPU inference, Vulkan capability, and documented CPU fallback.release-preflight.mjs against the previous published components.json.components.json, SHA256SUMS.txt, provenance statement, and BOM. Re-download all assets and re-verify every file against SHA256SUMS.txt before marking the run successful.The release must fail closed if the hosting platform cannot guarantee immutability. A rerun uses a new tag and sequence; it never edits an existing release.
There is no signing step and no trusted-keys material. The Engine does not read components.json or SHA256SUMS.txt at runtime for the whisper.cpp zips — it compiles the URL, byte size and SHA-256 into the Engine binary itself and installs an archive only when both match. SHA256SUMS.txt follows the same format native app releases use and is what post-publish re-verification and any future runtime-checked components consume.
Releases are append-only. Rollback selects a previously published, non-superseded component coordinate; it does not replace an asset or decrement the published sequence. A bad component is superseded by a later release with a new sequence pointing to the corrected artifact.