Open Source · Verification
Verify the bytes before trusting the claim.
The fresh v0.50.0 source archive used for publication has this SHA-256:
34f709139cfc62dd9e55c8354e294b2d5b23d2f2eac572dd5e769a9539d7e21c ruleoak-v0.50.0-source-3.zipSource checks completed before GitHub publication
- Source manifest: 713/713 PASS.
- Workspace tests and automatic QA: PASS after repository bootstrap.
- Licensing/legal metadata: PASS.
- Public/private boundary and public-launch checks: PASS.
- Workflow security and npm pack-content checks: PASS.
- Release reproducibility checks: PASS.
Public repository verification
- Verify the repository first commit matches the v0.50.0 source tree.
- Review GitHub-hosted CI/security results.
- Verify the
v0.50.0tag/release points to the intended public source state. - Record the resulting commit/tag identity with release evidence.
This page intentionally does not hard-code a Git commit hash into the website package. Verify the live repository and tag directly.
npm boundary
If @ruleoak/* packages are published separately, verify their exact package versions and packed contents before treating npm-specific commands as publicly runnable.