AsiBackbone 7.0.0 Consumer Verification Guide
Use this guide to verify the 7.0.0 package family after publication. It does
not claim that the packages are author-signed, independently audited,
certified, or reproducibly built by every consumer environment.
Confirm the package source
Install stable packages from the official NuGet source and verify the package owner, package ID, and selected version before adoption. Expected package IDs are:
AsiBackbone.CoreAsiBackbone.DependencyInjectionAsiBackbone.Storage.InMemoryAsiBackbone.EntityFrameworkCoreAsiBackbone.AspNetCoreAsiBackbone.TestingAsiBackbone.TemplatesAsiBackbone.AnalyzersAsiBackbone.OpenTelemetryAsiBackbone.Signing.LocalDevelopmentAsiBackbone.Signing.ManagedKey
Verify that the selected version is exactly 7.0.0.
Confirm the compatibility boundary
For 7.0.0, verify:
- target framework:
net10.0; - package version:
7.0.0; - assembly and file versions:
7.0.0.0; - repository URL:
https://github.com/AsiBackbone/AsiBackbone; and - package IDs and public namespaces remain in the
AsiBackbone.*family, with theHandshakesandCapabilityTokensnamespaces renamed toAcknowledgmentsandCapabilityGrants.
7.0.0 is a major release with intentional source, binary, behavior, schema,
and serialization breaks. Follow the
Upgrade from 6.x to 7.0 guide, rebuild every dependent
assembly, apply and verify the database migration, and run the host's
governance, acknowledgment, persistence, serialization, DLP, and endpoint tests
as applicable.
Check the breaking changes before adoption
- Actor-bound acknowledgment: the actor answering a challenge must have the
same
ActorIdandActorTypeas the actor that received it. Confirm actor resolution is stable across both request legs and handleacknowledgment.challenge.actor_mismatch. - Known actor binding: confirm challenge creation and response handling
reject unknown, unauthenticated,
Unknown-typed, and shared"unknown"actors asacknowledgment.challenge.actor_unbound. - Capability-grant binding: construct execution-boundary validation with
CreateBoundExecutionBoundaryand host-ownedCapabilityGrantBindingExpectations. Confirm a grant issued for another subject or operation fails closed. - DLP enum values:
DlpFailureBehaviorandDlpIntentRiskLevelnow useUnspecified = 0, shifting every former numeric value by one. Remap stored, serialized, transmitted, or numerically configured values; name-based values remain stable. - Incomplete DLP policy: unassigned risk levels and behaviors now raise
ArgumentOutOfRangeExceptioninstead of inheriting permissive behavior. - Renamed API surface: the retained
AuditResidue*,LiabilityHandshake*,Handshake*, andCapabilityToken*types and members are renamed with no forwarding aliases. Confirm the host compiles against the new names and that no string, reflection, or configuration reference still names an old type. - EF Core schema: five columns are renamed. Confirm the host's migration renames them rather than dropping and re-adding them, and that row counts in the affected tables are unchanged after applying it to a copy of production data.
- Decision receipt JSON: serialized decision receipts, ledger records, and
emission envelopes use
decisionReceiptIdinstead ofauditResidueId. Confirm that queries and consumers read the new key and that stored6.xJSON is migrated or translated before it is deserialized. - Unchanged signed contracts: confirm that an artifact signed by a
6.xhost verifies under7.0.0, and that artifact tags and OpenTelemetry names seen by existing dashboards are unchanged. - Typed artifact verification: when the application consumes the typed
Artifactafter verification, useGovernanceArtifactVerifier.VerifyTypedAsyncwith the matching canonical-payload builder and signing options. - NCAT adapter contract: if the optional NCAT audit-completion adapter is
used, run
NcatContractVectorTestsand./scripts/Test-NcatContractVectorPin.ps1to verify the vendored versioned vectors against NCAT.
Verify Source Link repository metadata
After the packages are available on NuGet, run:
./scripts/Validate-Source-Link-commit-metadata.ps1 -Version 7.0.0
The repository commit should resolve to the tagged source revision used for the published package.
Verify durable release evidence
The v7.0.0 GitHub release should expose stable build packages, matching SPDX
JSON SBOMs, sbom-manifest.json, release-evidence-manifest.json, and a
retained copy of the release notes.
gh release download v7.0.0 --repo AsiBackbone/AsiBackbone --pattern 'AsiBackbone.Core.7.0.0.nupkg'
gh attestation verify ./AsiBackbone.Core.7.0.0.nupkg --repo AsiBackbone/AsiBackbone
gh attestation verify ./AsiBackbone.Core.7.0.0.spdx.json --repo AsiBackbone/AsiBackbone
GitHub attestation verification is bound to the downloaded subject digest.
Verify the NuGet.org distribution separately
NuGet.org repository-signs packages during ingestion, which changes the
.nupkg digest from the original attested build package retained on the GitHub
release. Verify a NuGet.org package separately:
dotnet nuget verify --all ./AsiBackbone.Core.7.0.0.nupkg
Do not treat the GitHub build-package attestation and NuGet.org repository signature as the same evidence.
Package-author-signing status
AsiBackbone packages remain intentionally published without maintainer author signing while the project is independently maintained. The NuGet Package Signing Decision Record defines the accepted residual risk, compensating controls, mandatory review boundary, and early re-evaluation triggers.
Source Link, SBOMs, provenance statements, GitHub release tags, NuGet.org repository signatures, retained release hashes, and public source availability are useful but distinct signals.
Verify the release record
Compare the published packages with:
- the
v7.0.0Git tag and GitHub release; - the 7.0.0 Release Notes;
- the 7.0.0 Release Readiness Record;
CHANGELOG.md,CITATION.cff, and.zenodo.json; and- CI, API compatibility, package validation, documentation, SBOM, provenance, dependency, and workflow-security results for the final release commit.
A missing or inconsistent artifact should be investigated rather than silently treated as equivalent evidence.
Host responsibilities remain unchanged
Package verification does not replace host-owned authentication, authorization, identity-claim trust, policy registration, execution enforcement, durable storage, key custody, replay protection, monitoring, incident response, legal review, or compliance interpretation.