Open Source · Verification

Verify the bytes before trusting the claim.

The fresh v0.50.0 source archive used for publication has this SHA-256:

34f709139cfc62dd9e55c8354e294b2d5b23d2f2eac572dd5e769a9539d7e21c  ruleoak-v0.50.0-source-3.zip

Source checks completed before GitHub publication

Public repository verification

  1. Verify the repository first commit matches the v0.50.0 source tree.
  2. Review GitHub-hosted CI/security results.
  3. Verify the v0.50.0 tag/release points to the intended public source state.
  4. Record the resulting commit/tag identity with release evidence.
This page intentionally does not hard-code a Git commit hash into the website package. Verify the live repository and tag directly.

npm boundary

If @ruleoak/* packages are published separately, verify their exact package versions and packed contents before treating npm-specific commands as publicly runnable.