{
  "checkedAt": "2026-09-21T15:00:43.168380+00:00",
  "method": "Codex read official URLs with web tool and compared named local implementation files; provider claims retained separately.",
  "sources": [
    {
      "sourceId": "SRC-001",
      "url": "https://json-schema.org/draft/2020-12/json-schema-core",
      "version": "2020-12, published 2022-06-16",
      "status": "observed-selected-sections",
      "claim": "Sections 8.1, 8.2, 9.3: dialect and reference identity. Use a real validator and a declared bounded offline profile, not arbitrary keyword ignoring.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-002",
      "url": "https://github.com/opencontainers/image-spec/blob/v1.1.0/descriptor.md",
      "version": "v1.1.0",
      "status": "observed-selected-sections",
      "claim": "Descriptor properties digest, size and media type are a precedent for byte identity, not publisher authentication. Original Vercy descriptors are not an OCI compliance claim.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-003",
      "url": "https://www.w3.org/TR/prov-dm/",
      "version": "W3C Recommendation 2013-04-30",
      "status": "observed-selected-sections",
      "claim": "Sections 5.1 and 5.2 distinguish entities, activities, attribution and derivation. Use a plan, execution and receipt without treating provenance as truth.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-004",
      "url": "https://semver.org/spec/v2.0.0.html",
      "version": "2.0.0",
      "status": "observed-selected-sections",
      "claim": "Rules 1-3 and 9 distinguish declared public API, immutable releases and prerelease labels. SemVer cannot itself establish business semantic compatibility.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-005",
      "url": "https://docs.npmjs.com/cli/v11/configuring-npm/package-lock-json/",
      "version": "CLI v11 documentation, observed 2026-09-21",
      "status": "observed-selected-sections",
      "claim": "Description and packages: a lock records exact installed resolution, separate from broad dependency requests. Align concept only; no npm execution or lifecycle hooks.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-006",
      "url": "https://go.dev/ref/mod#minimal-version-selection",
      "version": "Living reference observed 2026-09-21",
      "status": "observed-selected-sections",
      "claim": "MVS is a graph algorithm with ecosystem assumptions. Exact-closure-v1 deliberately does not claim MVS or SemVer range solving.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-007",
      "url": "https://ver.cy/model-agent-protocol.md",
      "version": "Observed 2026-09-21",
      "status": "observed-selected-sections",
      "claim": "Read pinned model instructions, preserve ownership and provenance, distinguish bindings and model semantics. Owner authority must be supplied independently of package text.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-008",
      "url": "https://ver.cy/skills/vercy/scripts/validate_dimension.py",
      "version": "Skill 0.4.0, observed 2026-09-21",
      "status": "observed-selected-sections",
      "claim": "Local V1 registry file requirements, V2 specification digest and path checks, V3 record semantics. This implementation is not full JSON Schema evaluation of nested objects.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-009",
      "url": "https://github.com/ver-cy/elmm/blob/a5c04a68adc082958baddaa6820bf20b73a18907/README.md",
      "version": "a5c04a68adc082958baddaa6820bf20b73a18907",
      "status": "observed-selected-sections",
      "claim": "Kernel isolation, typed composition and semantic fingerprint are architectural precedents. The profile is not a verified native package in the current public runtime index.",
      "normativeConformanceClaim": false
    },
    {
      "sourceId": "SRC-010",
      "url": "https://docs.python.org/3/library/os.html#os.rename",
      "version": "Python 3 documentation, observed 2026-09-21",
      "status": "observed-selected-sections",
      "claim": "Filesystem rename semantics motivate a fresh same-filesystem target. No distributed transaction or power-loss durability claim follows from one rename.",
      "normativeConformanceClaim": false
    }
  ],
  "licensing": "Original authored schemas/code. External standards are linked and paraphrased; no external schemas redistributed. Vercy companion artifacts retain Apache-2.0 licensing.",
  "limitations": [
    "A source URL is not source authenticity or certification.",
    "The ELMM repository comparison is bounded to architecture and frozen source identity, not a full conformance audit."
  ]
}
