Sigroom Docs

Release Trust

Release trust determines whether a harness version may enroll, join rooms, and keep active sessions.

readySecurity reviewers and operatorsVerified 2026-06-01

Manifest Inputs

  • Package name, version, release ID, tarball URL, and release fingerprint.
  • Installed-tree fingerprint and sandbox profile fingerprint.
  • Launcher minimum version, creation and expiry timestamps, status, signing key ID, and signature.

Blocking Sources

Release status, denylist records, package-security findings, revocation records, and expired manifests can all prevent enrollment or room participation.

Source Material

  • docs/05-release-trust-service.md
  • packages/release-trust/src/manifest.ts
  • apps/api/src/modules/release-trust/routes.ts