{
  "schema_version": "1.2",
  "release_version": "1.25.0",
  "reviewed_date": "2026-08-11",
  "claim_status": "UNAVAILABLE_NOT_AUTHORIZED",
  "canonical_human_page": "/stewardship-and-provenance/",
  "profile_id": "FUTURE_AUTHENTICATED_SCOPE",
  "active": false,
  "failure_behavior": "FAIL_CLOSED",
  "truth_boundary": "Future authenticated verification remains inactive. Succession/closure/recovery/freshness are unsigned local structural controls and cannot authenticate identity, delete history, or activate production assurance.",
  "required_verification_material": {
    "signed_content": {
      "dsse_envelope_with_nonempty_signatures": "REQUIRED_NOT_AVAILABLE",
      "payload_type": "application/vnd.in-toto+json",
      "statement_subject_digest_match": "REQUIRED"
    },
    "identity_and_key_material": {
      "x509_certificate_chain_or_governed_public_key": "UNAVAILABLE",
      "expected_signer_or_workload_identity": "UNAVAILABLE",
      "expected_oidc_issuer_or_trust_root": "UNAVAILABLE",
      "certificate_or_key_validity_policy": "UNAVAILABLE"
    },
    "signature_validation": {
      "pae_recomputation": "REQUIRED",
      "signature_algorithm_policy": "UNAVAILABLE",
      "signature_verification_against_governed_key_material": "REQUIRED_NOT_CONFIGURED"
    },
    "trusted_time": {
      "policy": "UNAVAILABLE",
      "accepted_sources": [
        "RFC3161_SIGNED_TIMESTAMP_OR_EQUIVALENT_GOVERNED_TIME",
        "REKOR_INTEGRATED_TIME_IF_POLICY_ACCEPTS"
      ],
      "must_validate_certificate_at_trusted_time": true
    },
    "transparency_or_offline_bundle": {
      "policy": "UNAVAILABLE",
      "acceptable_evidence": [
        "GOVERNED_TRANSPARENCY_LOG_ENTRY_WITH_INCLUSION_EVIDENCE",
        "OFFLINE_VERIFICATION_BUNDLE_WITH_GOVERNED_TRUST_ROOT"
      ],
      "evidence_present": false
    },
    "release_binding": {
      "release_version": "1.20.0",
      "subject": "data/stewardship-provenance.json",
      "subject_sha256": "UNAVAILABLE_UNTIL_SIGNED_BUNDLE_EXISTS",
      "bundle_version_policy": "REQUIRED_NOT_CONFIGURED"
    }
  },
  "activation_requirements": [
    "separate owner authorization grant satisfying the migration-authorization envelope",
    "expected identity/issuer or trust-root policy is configured",
    "DSSE signatures are present and cryptographically verified over exact PAE bytes",
    "subject digest matches the governed release evidence",
    "trusted-time policy succeeds",
    "transparency-log or offline-bundle evidence succeeds under a governed trust root",
    "bundle and release versions match",
    "all fail-closed fixtures pass"
  ],
  "official_references": [
    {
      "project": "DSSE",
      "url": "https://github.com/secure-systems-lab/dsse/blob/master/protocol.md",
      "finding": "DSSE authenticates payload type and payload bytes through PAE; key management and PKI are separate concerns."
    },
    {
      "project": "Sigstore verification",
      "url": "https://docs.sigstore.dev/cosign/verifying/verify/",
      "finding": "Identity-based verification requires an expected certificate identity and OIDC issuer; bundle-based blob verification can carry certificate/signature evidence."
    },
    {
      "project": "Sigstore quickstart",
      "url": "https://docs.sigstore.dev/quickstart/quickstart-cosign/",
      "finding": "A verification bundle can contain signature, certificate, and log-inclusion proof; signed time is used when checking short-lived signing certificates."
    }
  ],
  "does_not_establish": "That Sigstore/cosign is installed, that a future bundle is trustworthy, that any identity is authorized, or that authenticated stewardship currently exists.",
  "candidate_target_version": "1.25.0",
  "structural_policy": "data/stewardship-verification-bundle-structure.json",
  "test_fixture_policy": "TEST_ONLY_STRUCTURAL_VALIDATION_CANNOT_ADVANCE_ASSURANCE",
  "migration_authorization_policy": "data/stewardship-verification-migration-authorization.json",
  "owner_authorization_grant_schema": "data/future-owner-authorization-grant-schema.json",
  "authorization_decision_ledger": "data/future-owner-authorization-decision-ledger.json",
  "authorization_decision_lifecycle": "data/future-owner-authorization-decision-lifecycle.json",
  "authorization_decision_currentness": "data/future-owner-authorization-decision-currentness.json",
  "resolver_checkpoint_controls": [
    "data/claim-reliance-resolver-checkpoints.json",
    "data/authorization-decision-lifecycle-checkpoints.json"
  ],
  "escalation_acknowledgement_receipts": "data/escalation-acknowledgement-receipts.json",
  "cross_resolver_consistency": "data/cross-resolver-consistency.json",
  "checkpoint_succession": "data/checkpoint-succession.json",
  "escalation_acknowledgement_closure_receipts": "data/escalation-acknowledgement-closure-receipts.json",
  "structural_state_recovery_proofs": "data/structural-state-recovery-proofs.json",
  "checkpoint_freshness": "data/checkpoint-freshness.json",
  "cross_resolver_recovery_consistency": "data/cross-resolver-recovery-consistency.json",
  "api_surface": "stewardship_verification_bundle_readiness"
}
