{"_id":"@avee1234/provenant","_rev":"4-064d885bd1574bdaf305a55c102ca8ed","name":"@avee1234/provenant","dist-tags":{"latest":"0.3.1"},"versions":{"0.1.0":{"name":"@avee1234/provenant","version":"0.1.0","keywords":["ai","agent","provenance","attestation","audit","verifiable","content-address","ledger","zero-dependency","claude-code","codex","cursor","antigravity"],"license":"MIT","_id":"@avee1234/provenant@0.1.0","maintainers":[{"name":"avee1234","email":"das.abhijit34@gmail.com"}],"bin":{"provenant":"bin/provenant.js"},"dist":{"shasum":"b2b430f5d4244745b31aa12a22a872402e99b7b9","tarball":"https://registry.npmjs.org/@avee1234/provenant/-/provenant-0.1.0.tgz","fileCount":12,"integrity":"sha512-0KotKaChzdDcjL1BwX0y1Mczhoiw8DS/9p/jiKCXLZPxrD7mfBQN3qP7ItYZfDoB9eJ0N1l8VidfU5oou8CkbA==","signatures":[{"sig":"MEUCICtPXgtmiudHeQl44TlLxVqcdEuc1qgCHHcQOIii5bDYAiEA/qeD8TcYDAorP/e7iUGbAfQtB/e9rW9S9HaGu9AnsyA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":71570},"main":"src/index.js","type":"module","engines":{"node":">=18"},"gitHead":"3b0b760966d70cfa12f92507fd5f5b76fd2568cf","scripts":{"test":"node --test"},"_npmUser":{"name":"avee1234","email":"das.abhijit34@gmail.com"},"_npmVersion":"10.9.8","description":"The open provenance format for AI-agent work. A verifiable, portable, append-only ledger of which agent produced which artifact, why, and derived from what — with content-hash IDs, offline verification, provenance chains, and optional HMAC tamper-evidence","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/provenant_0.1.0_1784000379345_0.08454468515503377","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@avee1234/provenant","version":"0.2.0","keywords":["ai","agent","provenance","attestation","audit","verifiable","content-address","ledger","zero-dependency","opentelemetry","ed25519","signatures","claude-code","codex","cursor","antigravity"],"license":"MIT","_id":"@avee1234/provenant@0.2.0","maintainers":[{"name":"avee1234","email":"das.abhijit34@gmail.com"}],"bin":{"provenant":"bin/provenant.js"},"dist":{"shasum":"a67dcc21bbb45027583a3be8dd94ec43d4b8a19e","tarball":"https://registry.npmjs.org/@avee1234/provenant/-/provenant-0.2.0.tgz","fileCount":14,"integrity":"sha512-z8MS3RZQ+YfOI9Wduwv8Uo0OLWEDqGcaRMsW2DDRXW/LdckvQbfY7okuT8ED/yTJ2TcXk00VDgnPVX2ICDYx3g==","signatures":[{"sig":"MEUCIQC1VJslPf1GBZ2n5Qo57DtZkjAbupxLMBB2KvfStRcLcAIgUv88TVGvP5eMWltjGak3vadEC/F1kPZdEkJQEUdxqJM=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":86146},"main":"src/index.js","type":"module","engines":{"node":">=18"},"gitHead":"13daf4c836d684a614441e972ce4fc0b45b57bc3","scripts":{"test":"node --test"},"_npmUser":{"name":"avee1234","email":"das.abhijit34@gmail.com"},"_npmVersion":"10.9.8","description":"The open provenance format for AI-agent work. A verifiable, portable, append-only ledger of which agent produced which artifact, why, and derived from what — with content-hash IDs, offline verification, provenance chains, and optional HMAC or ed25519 tamp","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/provenant_0.2.0_1784054646682_0.5077088840373332","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@avee1234/provenant","version":"0.3.0","keywords":["ai","agent","provenance","attestation","audit","verifiable","content-address","ledger","evaluation","confidence","eval","zero-dependency","opentelemetry","ed25519","signatures","claude-code","codex","cursor","antigravity"],"license":"MIT","_id":"@avee1234/provenant@0.3.0","maintainers":[{"name":"avee1234","email":"das.abhijit34@gmail.com"}],"bin":{"provenant":"bin/provenant.js"},"dist":{"shasum":"00df9da1031da25df22ae7ebfd3ee31b27859392","tarball":"https://registry.npmjs.org/@avee1234/provenant/-/provenant-0.3.0.tgz","fileCount":15,"integrity":"sha512-p6o+7fp8FUzUcGE+OBXhEok3NutsSyNByUc3wqSJ07/PE8njc+iRTqihqYIJnC+H6Ub+HawrrbFmYCINJpHcdw==","signatures":[{"sig":"MEUCIFoJOVXkWmPS0OunLzf2+aN+19IKZWdGXu1Y+80f/HHLAiEArds1gOZLxawRfkzgcCRsbDvd7pzplGX7b9KGUO719lo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":112595},"main":"src/index.js","type":"module","engines":{"node":">=18"},"gitHead":"bdd1b49b8fffa51aa7578c3c192bbf639a8e88cd","scripts":{"test":"node --test"},"_npmUser":{"name":"avee1234","email":"das.abhijit34@gmail.com"},"_npmVersion":"10.9.8","description":"The open provenance format for AI-agent work. A verifiable, portable, append-only ledger of which agent produced which artifact, why, and derived from what — with content-hash IDs, offline verification, provenance chains, and optional HMAC or ed25519 tamp","directories":{},"_nodeVersion":"22.22.3","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/provenant_0.3.0_1784073099900_0.6500762809517973","host":"s3://npm-registry-packages-npm-production"}},"0.3.1":{"name":"@avee1234/provenant","version":"0.3.1","description":"The open provenance format for AI-agent work. A verifiable, portable, append-only ledger of which agent produced which artifact, why, and derived from what — with content-hash IDs, offline verification, provenance chains, and optional HMAC or ed25519 tamp","type":"module","main":"src/index.js","bin":{"provenant":"bin/provenant.js"},"engines":{"node":">=18"},"scripts":{"test":"node --test"},"keywords":["ai","agent","provenance","attestation","audit","verifiable","content-address","ledger","evaluation","confidence","eval","zero-dependency","opentelemetry","ed25519","signatures","claude-code","codex","cursor","antigravity"],"license":"MIT","gitHead":"049c11aeee69080ccc8653b24ec37a8d73cd75df","_id":"@avee1234/provenant@0.3.1","_nodeVersion":"25.8.0","_npmVersion":"11.11.0","dist":{"integrity":"sha512-YU9r+hLWmnYvAxA4jKeWnHfCaMdpnzLMqZ5IDKLrPmFVdoILmJE4krflP076pp0ewbCo1pQ/tU58+KVCi6FYZQ==","shasum":"8b0bf363b37588961b42d17edf53b5ed1a3c212e","tarball":"https://registry.npmjs.org/@avee1234/provenant/-/provenant-0.3.1.tgz","fileCount":15,"unpackedSize":116432,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIB4h9/xRnnteEvufgRchJzRiza70FFb2oS4sqMSWoqlcAiB0znnpTCHoKmW3Hqp6esDvLoSiDtnR0zcXC8QB/mTrzw=="}]},"_npmUser":{"name":"avee1234","email":"das.abhijit34@gmail.com"},"directories":{},"maintainers":[{"name":"avee1234","email":"das.abhijit34@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/provenant_0.3.1_1784123952889_0.7493747829436599"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-14T03:39:39.244Z","modified":"2026-07-15T13:59:13.147Z","0.1.0":"2026-07-14T03:39:39.470Z","0.2.0":"2026-07-14T18:44:06.830Z","0.3.0":"2026-07-14T23:51:40.055Z","0.3.1":"2026-07-15T13:59:13.041Z"},"license":"MIT","keywords":["ai","agent","provenance","attestation","audit","verifiable","content-address","ledger","evaluation","confidence","eval","zero-dependency","opentelemetry","ed25519","signatures","claude-code","codex","cursor","antigravity"],"description":"The open provenance format for AI-agent work. A verifiable, portable, append-only ledger of which agent produced which artifact, why, and derived from what — with content-hash IDs, offline verification, provenance chains, and optional HMAC or ed25519 tamp","maintainers":[{"name":"avee1234","email":"das.abhijit34@gmail.com"}],"readme":"# provenant\n\n**The open provenance format for AI-agent work.** When an agent produces something — a file, a patch, a generated asset — it writes an *attestation*: a small, verifiable record of *which agent* produced *which artifact*, *why*, and *derived from what*. The records form an append-only, content-addressed ledger anyone can verify offline. So a repo full of agent-written work finally has a portable, tamper-evident authorship trail. Zero dependencies.\n\n> Working name — see [`vision.md`](vision.md). Grounded in the mid-2026 state of agent-authored codebases.\n\nCoding agents now write a large and growing share of the code, docs, and assets in a repo — Claude Code, Codex, Cursor, and Google Antigravity all commit on their own — but the work lands with **no verifiable record of where it came from**. `git blame` shows the human who ran the agent, not the model, the harness, the intent, or the upstream artifacts it derived from. Reviewers can't tell agent output from human output; security teams can't audit which artifacts a misconfigured agent touched; and every harness that gestures at \"signed agent commits\" does it in its own private, non-portable way. provenant is the missing layer: an open format for *authorship and derivation*, not another platform.\n\n```bash\nnpx @avee1234/provenant attest src/auth.js --intent \"add OAuth\"   # record what I produced\nnpx @avee1234/provenant verify src/auth.js                        # is this attested, and by whom?\nnpx @avee1234/provenant chain <id>                                # what did it derive from?\nnpx @avee1234/provenant coverage src/**/*.js                      # what fraction of the repo is attested?\nnpx @avee1234/provenant revoke <id> --reason \"superseded\"         # supersede an attestation\nnpx @avee1234/provenant hook install                              # auto-attest every file a commit changes\n```\n\n**Why it's different:** content-addressed, so verification is *trustless* — an attestation names an artifact by the sha256 of its bytes, so anyone can re-hash the file and check the record offline, with no appeal to the tool that wrote it. The ledger is append-only JSONL with content-hash IDs, so many agents writing attestations at once can't corrupt it or merge-conflict it with itself. Harness-neutral: Claude Code, Codex, Cursor, Google Antigravity, or a factory worker — anything that can run a CLI or import a function.\n\nSame open-format-and-conformance playbook as [opentrajectory](https://github.com/abhid1234/opentrajectory) (traces) and [worklease](https://github.com/abhid1234/worklease) (coordination) — the provenance standard for the one thing an agent fleet can't currently prove: *which agent produced which artifact, why, and from what.*\n\n## The attestation format\n\nAn attestation is one JSON object. `id` is the sha256 content hash of the record itself (its own `id` excluded), so a record's identity *is* its content — a tampered line no longer matches its id and is dropped on read. `artifact` is the sha256 of the artifact's bytes, so verification never needs the bytes stored in the ledger.\n\n```json\n{\n  \"id\": \"325be403c7480ede4648a3aac500437b545b6a41c0323daf08d2793ed9595e9a\",\n  \"type\": \"attestation\",\n  \"agent\": \"claude-opus-4-8/claude-code\",\n  \"artifact\": \"b94d27b9934d3e08a52e52d7da7dabfac484efe37a5380ee9088f7ace2efcde9\",\n  \"intent\": \"add OAuth login flow\",\n  \"parents\": [\"a1b2c3…\"],\n  \"created\": \"2026-07-11T12:00:00Z\",\n  \"meta\": { \"harness\": \"git\", \"commit\": \"deadbeef…\", \"path\": \"src/auth.js\" },\n  \"signature\": \"f0e1d2…\"\n}\n```\n\n- `agent` — **who** produced the artifact (model / harness identity).\n- `artifact` — **what**, as the sha256 hex of its content.\n- `intent` — **why** it was produced (non-empty).\n- `parents` — **from what** — the attestation ids this work derives from (`chain` walks these back to origins).\n- `created` — an ISO-8601-**UTC** timestamp (`…Z`; offsets and impossible calendar dates are rejected).\n- `meta` *(optional)* — free-form context (harness / model / session / path).\n- `signature` *(optional)* — a digest proving *who wrote the record*, not just what it says: HMAC-sha256 (shared secret) or an ed25519 signature (cross-org, no shared secret).\n\nA **revocation** supersedes an attestation: `{ id, type: \"revocation\", attestation_id, agent, reason, at }`. Revocations are appended, never deletions — the ledger stays append-only, and `verify` folds them in at read time.\n\n## Library API\n\nZero-dependency ESM. `import { … } from \"@avee1234/provenant\"`. Every function is pure and clock-injected (no I/O except the ledger store), so the whole core is deterministic and unit-testable.\n\n**Schema & validation** — never throw; each returns `{ valid, errors }` collecting *every* violation.\n- `validateAttestation(obj)` / `validateRevocation(obj)` / `validateLedger(arr)`\n- `validateEvaluation(evaluation)` — the optional evaluation claim (`{ score, method, checks?, evaluator? }`)\n- `isSha256Hex(s)`, `isIso8601Utc(s)` — the two format primitives\n- `ATTESTATION_FIELDS`, `REVOCATION_FIELDS`, `EVALUATION_FIELDS`, `EVAL_METHODS`, `RECORD_TYPES`, `ERROR_CODES`\n\n**Hash & construct** — pure record constructors (throw on bad input rather than emit a malformed record).\n- `computeHash(content)` → the sha256 hex of a string/Buffer (the artifact fingerprint)\n- `attest(content, { agent, intent, parents, created, meta, evaluation })` → an attestation record. `content` is a string/Buffer (hashed here) or `{ hash }` (a pre-computed digest). The optional `evaluation` is validated and folded into the hashed content.\n- `revoke(attestationId, { agent, reason, at })` → a revocation record\n- `computeRecordId(record)` / `canonicalize(record)` — the content-hash id primitives\n\n**Ledger store** — the append-only JSONL layer.\n- `loadLedger(path)` → `{ attestations, notes }` (missing file → empty, no throw; folds revocations, drops tampered/unparseable lines with a note)\n- `appendRecord(path, record)` — append exactly one line (`O_APPEND`); existing lines are never rewritten\n- `resolveRecords(records)` → fold a raw log into the current attestation array\n- `defaultLedgerPath(cwd)` — `PROVENANT_LEDGER`, else `.provenant/ledger.jsonl`\n- `listAttestations`, `shortId`\n\n**Verify & query** — pure, offline, over a resolved array.\n- `verify(artifactHash, attestations)` → `{ attested, record, revoked }`\n- `chainOf(attestationId, attestations)` → the ordered provenance chain (record + ancestors via `parents`, deduped and cycle-safe)\n- `coverage(artifactHashes, attestations)` → `{ score, total, attested, unattested, revoked }`\n\n**Evaluation & confidence** *(the attested-quality-claim query layer)*\n- `evalOf(artifactHash, attestations)` → the live evaluation claim `{ score, method, checks, evaluator, agent }` (latest non-revoked attestation carrying an `evaluation`), or `null`\n- `evalCoverage(artifactHashes, attestations, { threshold? })` → the confidence audit `{ evaluated, unevaluated, mean_score, min_score, below }` — which outputs are low-confidence or unevaluated\n\n**Sign** *(optional HMAC tamper-evidence — shared secret)*\n- `sign(record, secret)` → HMAC-sha256 hex over the record's canonical pre-image\n- `verifySignature(record, secret)` → constant-time boolean\n\n**Sign (ed25519)** *(optional asymmetric tamper-evidence — cross-org, no shared secret)*\n- `generateKeypair()` → `{ publicKey, privateKey }` PEM strings (SPKI / PKCS#8)\n- `signAsym(record, privateKeyPem)` → a detached ed25519 signature (hex) over the same canonical pre-image\n- `verifyAsym(record, publicKeyPem, signatureHex?)` → boolean; pass `signatureHex` (detached) or omit it to verify the record's own `signature` (embedded). Never throws — a bad key/signature is `false`.\n\n**OpenTelemetry** *(pure record → span-attribute bridge)*\n- `attestationToSpanAttributes(record)` → a FLAT `provenant.*` attribute object (scalars only; `parents` joined to a comma string, plus `parent_count`, `revoked`, `signed`, and `eval.*` when an evaluation is present)\n- `coverageToSpanAttributes(report)` → a FLAT `provenant.coverage.*` attribute object from a `coverage()` result\n\n**Git adapter** *(the dogfood surface)*\n- `attestCommit({ cwd, agent, ledger, created, intent })`, `changedPaths`, `installHook`, `hookPath`, `renderHookBlock`\n\n## CLI\n\n```bash\nprovenant attest <file> --intent \"<why>\" [--agent <id>] [--parents <ids>]\n                        [--eval-score <0..1> --eval-method <m>] [--eval-check <name:pass> ...] [--ledger <path>] [--json]\nprovenant verify <file-or-hash> [--ledger <path>] [--json]\nprovenant chain <attestation-id> [--ledger <path>] [--json]\nprovenant coverage <path...> [--ledger <path>] [--json]\nprovenant eval <file-or-hash> [--ledger <path>] [--json]\nprovenant confidence <path...> [--threshold <0..1>] [--ledger <path>] [--json]\nprovenant log [--all] [--agent <id>] [--ledger <path>] [--json]\nprovenant revoke <attestation-id> --reason \"<why>\" [--agent <id>] [--ledger <path>] [--json]\nprovenant hook install [--ledger <path>]\nprovenant hook run [--agent <id>] [--ledger <path>] [--json]\nprovenant otel <ledger-file> [--coverage <path...>]\n```\n\n- **`attest <file>`** — hash the file's content and append an attestation: which agent produced it, why, and what it derives from. The record is validated before it's written. Exit `0` on write. With `--eval-score` + `--eval-method` (and optional repeatable `--eval-check name:pass|fail`), the attestation also carries an **evaluation** — an attested claim about the artifact's quality/confidence, folded into the content hash so it can't be silently edited.\n- **`verify <file-or-hash>`** — is the artifact (a file, hashed here, or a raw sha256 digest) attested? Exit `0` if a live attestation exists, `1` if unattested or revoked.\n- **`chain <id>`** — print the provenance chain of an attestation (the record and every ancestor via `parents`). Accepts a full id or an unambiguous prefix. Exit `1` if the id is unknown.\n- **`coverage <path...>`** — audit what fraction of the given files carry a live attestation. Exit `0` when all are attested, `1` when any is unattested or revoked.\n- **`eval <file-or-hash>`** — print the live evaluation claim for an artifact (score, method, checks, evaluator, agent). Exit `0` if a claim exists, `1` if none.\n- **`confidence <path...>`** — the confidence audit: which of the given files are low-confidence or unevaluated? Reports evaluated/unevaluated counts, mean + min score, and (with `--threshold`) the files scoring below it. Exit `0` when all are evaluated and none is below the threshold, `1` otherwise.\n- **`log`** — list the ledger's live attestations (who produced what, why, from what). `--all` also shows revoked ones, labeled; `--agent` filters to one producer.\n- **`revoke <id> --reason`** — supersede an attestation by appending a revocation. A no-op with a note if it is already revoked (still exit `0`).\n- **`hook install` / `hook run`** — install a **git post-commit hook** that attests every file a commit changed, chaining each new version to the previous attestation of the same path. Post-commit (not pre-commit) is deliberate: provenance records what *did* happen, and the hook only ever appends — it never blocks or alters a commit. Install is idempotent and preserves any existing hook (it manages only a marked block).\n- **`otel <ledger-file>`** — emit OpenTelemetry-style span attributes (JSON) for the ledger: one flat `provenant.*` attribute object per attestation. With `--coverage <path...>`, instead emit the single `provenant.coverage.*` attribute object auditing those files against the ledger.\n\nCommon flags: `--agent <id>` (or `PROVENANT_AGENT`), `--ledger <path>` (or `PROVENANT_LEDGER`, default `.provenant/ledger.jsonl`), `--json` for machine-readable output.\n\n## The ledger\n\nThe store is an **append-only JSONL file** (default `.provenant/ledger.jsonl`), meant to be **committed** so the provenance trail travels with the repo across worktrees and harnesses. New records are appended as whole lines; existing lines are never rewritten. Every record's `id` is a content hash of its own content, so a duplicated append is idempotent on read and two agents appending at once union-merge cleanly instead of conflicting. A line that fails its integrity check (its `id` no longer matches its content — i.e. it was tampered) or won't parse is skipped with a note surfaced to stderr — one bad line never discards the rest of the ledger.\n\n## Evaluation / confidence claims\n\nprovenant records not just *who* made an artifact but an attested, verifiable **claim about its quality**. An attestation can carry an optional `evaluation` — a portable, content-addressed assertion of the artifact's confidence/quality score and *how it was judged*:\n\n```json\n{\n  \"id\": \"…\", \"type\": \"attestation\",\n  \"agent\": \"claude-opus-4-8/claude-code\",\n  \"artifact\": \"b94d27b9…\",\n  \"intent\": \"add OAuth login flow\",\n  \"created\": \"2026-07-11T12:00:00Z\",\n  \"evaluation\": {\n    \"score\": 0.9,\n    \"method\": \"test\",\n    \"checks\": [\n      { \"name\": \"unit-tests\", \"passed\": true },\n      { \"name\": \"typecheck\", \"passed\": true, \"note\": \"no errors\" }\n    ],\n    \"evaluator\": \"vitest@2\"\n  }\n}\n```\n\n- `score` — the claimed quality/confidence, a number in `[0, 1]`.\n- `method` — **how** it was judged: `self` | `test` | `judge` | `human` | any bespoke evaluator name (the well-known set is `EVAL_METHODS`; any non-empty string is allowed).\n- `checks` *(optional)* — named boolean sub-checks `{ name, passed, note? }` — the receipts behind the score.\n- `evaluator` *(optional)* — who/what produced the judgement.\n\nBecause the `evaluation` is part of the **canonical record content**, the content-hash `id` (and any HMAC/ed25519 signature) *cover it* — the score can't be silently edited: rewrite a `0.9` to `0.1` and the record no longer matches its own `id`, so it's dropped on read, and any signature fails. An attestation with no `evaluation` behaves exactly as before this feature (byte-for-byte identical record, same `id`) — the addition is fully backward-compatible.\n\n**This is an attested *claim*, not runtime verification.** provenant does not re-execute the artifact or check the score against reality — it records \"this agent *asserts* this artifact scores 0.9 by method=test, and here are the checks\", tamper-evidently, alongside the provenance. That makes evaluation scores auditable across a repo the way coverage is — distinct from a runtime outcome-verification sibling that would actually re-run the work.\n\n```bash\nprovenant attest src/auth.js --intent \"add OAuth\" \\\n  --eval-score 0.9 --eval-method test --eval-check unit:pass --eval-check lint:fail   # attest WITH a quality claim\nprovenant eval src/auth.js                          # what is the live evaluation claim? (score, method, checks)\nprovenant confidence src/**/*.js --threshold 0.8    # which outputs are low-confidence / unevaluated?\n```\n\n`evalOf(artifactHash, attestations)` returns the live claim (latest non-revoked evaluation), and `evalCoverage(hashes, attestations, { threshold })` returns `{ evaluated, unevaluated, mean_score, min_score, below }` — the fleet-wide \"which agent outputs are below the bar, or carry no quality claim at all?\" audit. Both are pure, offline, and zero-dep. Harness-neutral: Claude Code, Codex, Cursor, Google Antigravity, or a factory worker can all attach a score to what they produce.\n\n## OpenTelemetry\n\nprovenant projects records onto **span attributes** so provenance rides along with the traces an agent fleet already emits. `attestationToSpanAttributes(record)` returns a **flat** `provenant.*` object — `provenant.agent`, `provenant.artifact`, `provenant.intent`, `provenant.parents` (the ids joined to a comma string) with `provenant.parent_count`, `provenant.created`, and the `provenant.revoked` / `provenant.signed` booleans — values are only strings, numbers, and booleans, so any exporter accepts them with no nesting. When a record carries an evaluation, `provenant.eval.score` / `provenant.eval.method` / `provenant.eval.checks_passed` (and `provenant.eval.evaluator` when present) are emitted too, so the attested confidence rides along on the span. `coverageToSpanAttributes(coverage(…))` does the same for a repo audit under `provenant.coverage.*`. Both are pure and deterministic; `provenant otel <ledger>` prints them as JSON. Same bridge convention as the rest of the family (constraintguard's `cg otel`).\n\n## ed25519 signatures\n\nThe HMAC layer proves authorship to anyone holding the shared secret — which is everyone who can verify, so it can't prove authorship *across* an org boundary. The optional **ed25519** layer closes that: the author signs with a private key nobody else holds, and anyone verifies with the matching public key — cross-org tamper-evidence with no shared secret. `generateKeypair()` mints a keypair (SPKI / PKCS#8 PEM), `signAsym(record, privateKeyPem)` signs the *same* canonical pre-image the ledger already hashes, and `verifyAsym(record, publicKeyPem, signatureHex?)` verifies the detached signature or the record's own embedded `signature`. Node's built-in `crypto` only — zero external dependency. Layered on top like HMAC; never required to attest or verify.\n\n## Install\n\n```bash\nnpm install @avee1234/provenant      # library\nnpx @avee1234/provenant attest …     # CLI, no install\n```\n\nRequires Node ≥ 18. Run the test suite with `node --test`.\n\nStatus: **v0.3** — see [`roadmap.md`](roadmap.md). MIT · zero dependencies · harness-neutral.\n","readmeFilename":"README.md"}