Table of Contents

AsiBackbone 7.0.0 Consumer Verification Guide

Use this guide to verify the 7.0.0 package family after publication. It does not claim that the packages are author-signed, independently audited, certified, or reproducibly built by every consumer environment.

Confirm the package source

Install stable packages from the official NuGet source and verify the package owner, package ID, and selected version before adoption. Expected package IDs are:

  • AsiBackbone.Core
  • AsiBackbone.DependencyInjection
  • AsiBackbone.Storage.InMemory
  • AsiBackbone.EntityFrameworkCore
  • AsiBackbone.AspNetCore
  • AsiBackbone.Testing
  • AsiBackbone.Templates
  • AsiBackbone.Analyzers
  • AsiBackbone.OpenTelemetry
  • AsiBackbone.Signing.LocalDevelopment
  • AsiBackbone.Signing.ManagedKey

Verify that the selected version is exactly 7.0.0.

Confirm the compatibility boundary

For 7.0.0, verify:

  • target framework: net10.0;
  • package version: 7.0.0;
  • assembly and file versions: 7.0.0.0;
  • repository URL: https://github.com/AsiBackbone/AsiBackbone; and
  • package IDs and public namespaces remain in the AsiBackbone.* family, with the Handshakes and CapabilityTokens namespaces renamed to Acknowledgments and CapabilityGrants.

7.0.0 is a major release with intentional source, binary, behavior, schema, and serialization breaks. Follow the Upgrade from 6.x to 7.0 guide, rebuild every dependent assembly, apply and verify the database migration, and run the host's governance, acknowledgment, persistence, serialization, DLP, and endpoint tests as applicable.

Check the breaking changes before adoption

  • Actor-bound acknowledgment: the actor answering a challenge must have the same ActorId and ActorType as the actor that received it. Confirm actor resolution is stable across both request legs and handle acknowledgment.challenge.actor_mismatch.
  • Known actor binding: confirm challenge creation and response handling reject unknown, unauthenticated, Unknown-typed, and shared "unknown" actors as acknowledgment.challenge.actor_unbound.
  • Capability-grant binding: construct execution-boundary validation with CreateBoundExecutionBoundary and host-owned CapabilityGrantBindingExpectations. Confirm a grant issued for another subject or operation fails closed.
  • DLP enum values: DlpFailureBehavior and DlpIntentRiskLevel now use Unspecified = 0, shifting every former numeric value by one. Remap stored, serialized, transmitted, or numerically configured values; name-based values remain stable.
  • Incomplete DLP policy: unassigned risk levels and behaviors now raise ArgumentOutOfRangeException instead of inheriting permissive behavior.
  • Renamed API surface: the retained AuditResidue*, LiabilityHandshake*, Handshake*, and CapabilityToken* types and members are renamed with no forwarding aliases. Confirm the host compiles against the new names and that no string, reflection, or configuration reference still names an old type.
  • EF Core schema: five columns are renamed. Confirm the host's migration renames them rather than dropping and re-adding them, and that row counts in the affected tables are unchanged after applying it to a copy of production data.
  • Decision receipt JSON: serialized decision receipts, ledger records, and emission envelopes use decisionReceiptId instead of auditResidueId. Confirm that queries and consumers read the new key and that stored 6.x JSON is migrated or translated before it is deserialized.
  • Unchanged signed contracts: confirm that an artifact signed by a 6.x host verifies under 7.0.0, and that artifact tags and OpenTelemetry names seen by existing dashboards are unchanged.
  • Typed artifact verification: when the application consumes the typed Artifact after verification, use GovernanceArtifactVerifier.VerifyTypedAsync with the matching canonical-payload builder and signing options.
  • NCAT adapter contract: if the optional NCAT audit-completion adapter is used, run NcatContractVectorTests and ./scripts/Test-NcatContractVectorPin.ps1 to verify the vendored versioned vectors against NCAT.

After the packages are available on NuGet, run:

./scripts/Validate-Source-Link-commit-metadata.ps1 -Version 7.0.0

The repository commit should resolve to the tagged source revision used for the published package.

Verify durable release evidence

The v7.0.0 GitHub release should expose stable build packages, matching SPDX JSON SBOMs, sbom-manifest.json, release-evidence-manifest.json, and a retained copy of the release notes.

gh release download v7.0.0 --repo AsiBackbone/AsiBackbone --pattern 'AsiBackbone.Core.7.0.0.nupkg'
gh attestation verify ./AsiBackbone.Core.7.0.0.nupkg --repo AsiBackbone/AsiBackbone
gh attestation verify ./AsiBackbone.Core.7.0.0.spdx.json --repo AsiBackbone/AsiBackbone

GitHub attestation verification is bound to the downloaded subject digest.

Verify the NuGet.org distribution separately

NuGet.org repository-signs packages during ingestion, which changes the .nupkg digest from the original attested build package retained on the GitHub release. Verify a NuGet.org package separately:

dotnet nuget verify --all ./AsiBackbone.Core.7.0.0.nupkg

Do not treat the GitHub build-package attestation and NuGet.org repository signature as the same evidence.

Package-author-signing status

AsiBackbone packages remain intentionally published without maintainer author signing while the project is independently maintained. The NuGet Package Signing Decision Record defines the accepted residual risk, compensating controls, mandatory review boundary, and early re-evaluation triggers.

Source Link, SBOMs, provenance statements, GitHub release tags, NuGet.org repository signatures, retained release hashes, and public source availability are useful but distinct signals.

Verify the release record

Compare the published packages with:

  • the v7.0.0 Git tag and GitHub release;
  • the 7.0.0 Release Notes;
  • the 7.0.0 Release Readiness Record;
  • CHANGELOG.md, CITATION.cff, and .zenodo.json; and
  • CI, API compatibility, package validation, documentation, SBOM, provenance, dependency, and workflow-security results for the final release commit.

A missing or inconsistent artifact should be investigated rather than silently treated as equivalent evidence.

Host responsibilities remain unchanged

Package verification does not replace host-owned authentication, authorization, identity-claim trust, policy registration, execution enforcement, durable storage, key custody, replay protection, monitoring, incident response, legal review, or compliance interpretation.