{"_id":"@divinci-ai/trustbench-verifier","_rev":"7-15ecc0550edd21d819a5f415faacf26b","name":"@divinci-ai/trustbench-verifier","dist-tags":{"latest":"0.6.0"},"versions":{"0.1.0":{"name":"@divinci-ai/trustbench-verifier","version":"0.1.0","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.1.0","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"cb754b308f137417e7f198b511a15a24b7334060","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.1.0.tgz","fileCount":27,"integrity":"sha512-g6k81h0UyEgPMYjPMQC4EgXRvwEfhZK9Ch146NQRz3iPMTnnGVJPT9/JB/puqfvGpvPRNAZLNcHmNVtTW4x37Q==","signatures":[{"sig":"MEUCIQCSocCGmndwl/ERJX8Rneb8vpqEm6oyNEzBKIKPCOh2kwIgKyC6gfTRhz283TdM4kaYTS5zpHQ490PC8M/Nu1SwOJE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67807},"main":"./dist/index.js","_from":"file:divinci-ai-trustbench-verifier-0.1.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"mike-divinci","email":"mike@divinci.ai"},"_resolved":"/private/var/folders/sw/_w_lmwt94_n56fb8fp4dbhjh0000gn/T/68b1d35447b2e19d9688601555df0ab7/divinci-ai-trustbench-verifier-0.1.0.tgz","_integrity":"sha512-g6k81h0UyEgPMYjPMQC4EgXRvwEfhZK9Ch146NQRz3iPMTnnGVJPT9/JB/puqfvGpvPRNAZLNcHmNVtTW4x37Q==","repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git","directory":"packages/trustbench-verifier"},"_npmVersion":"11.12.1","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"26.0.0","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.1.0_1779436721169_0.6655478412058289","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@divinci-ai/trustbench-verifier","version":"0.1.1","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.1.1","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"87b28837e509363b9df9dc0684abe668e2cba1e3","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.1.1.tgz","fileCount":27,"integrity":"sha512-hXBUT1hd7UmoAePpCCRViBIP8Lhc0hTIPlN0ATyNrLu9PGTE0YqoRyleffFvVHUaBZurNhKJPWJRiBkY0/L3Mw==","signatures":[{"sig":"MEQCIAa1VPY7imUW/DcRvG3/uj7itIxbhkRwpZEcUcEIL26qAiBVY134OAKtjICVcodZ5qs21dfLQX3KRyY1+yOiE1w6Ig==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67773},"main":"./dist/index.js","_from":"file:divinci-ai-trustbench-verifier-0.1.1.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:68e68252-7ce3-4476-bad5-fe8bb730f45a"}},"_resolved":"/tmp/73ff38aef9004d7eb5e7ed6f9c9c9354/divinci-ai-trustbench-verifier-0.1.1.tgz","_integrity":"sha512-hXBUT1hd7UmoAePpCCRViBIP8Lhc0hTIPlN0ATyNrLu9PGTE0YqoRyleffFvVHUaBZurNhKJPWJRiBkY0/L3Mw==","repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"11.19.0","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.1.1_1787141474175_0.51066462931398","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@divinci-ai/trustbench-verifier","version":"0.2.0","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.2.0","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"9957981132da55e0cb69fa782c5f589dab2dcc2b","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.2.0.tgz","fileCount":27,"integrity":"sha512-N4TU+1/WHk2htzUArBjL2gmxb9H0Isw2AjXZHL2PfdjTjcibx34cuYt2g28efgecnsM4lDhE0OMEOjvCw5U/iw==","signatures":[{"sig":"MEUCIAW6PbO8CJTmrBymoFZrHTyXN4W3S2aOph3+uSyg5FTuAiEA+a+WLABvkNk9hLlFnuH3DpPJnQasefk1r9v8q5v8TwE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":84852},"main":"./dist/index.js","_from":"file:divinci-ai-trustbench-verifier-0.2.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:68e68252-7ce3-4476-bad5-fe8bb730f45a"}},"_resolved":"/tmp/77092f0326b4cc836ecb314a59e9acc5/divinci-ai-trustbench-verifier-0.2.0.tgz","_integrity":"sha512-N4TU+1/WHk2htzUArBjL2gmxb9H0Isw2AjXZHL2PfdjTjcibx34cuYt2g28efgecnsM4lDhE0OMEOjvCw5U/iw==","repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"11.19.1","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.2.0_1788686563376_0.21783475266823293","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@divinci-ai/trustbench-verifier","version":"0.3.0","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.3.0","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"3f8e83b5d193b905027787a6a95359eff8d51349","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.3.0.tgz","fileCount":35,"integrity":"sha512-riowD3QG4cpTw9G7UryX1jREvWtqBbIhRWfmDiKggr9q6Jix4oSFttkGTYzDIv66fJ6O4foxWSb3hsPipOR6sw==","signatures":[{"sig":"MEQCIFY34cBht3Gzp+uqw7TbGMRssQ3OgLYyjmg0w3L1kK8wAiBwlNCJQpUeXQEsBgl5cO680Ogz2wfBITl6F1PdSKf60A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":224410},"main":"./dist/index.js","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"gitHead":"e25b8f45409f29c0f8cccb328ad9e1b3b97c6f47","scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","prepack":"node ../../scripts/assert-packed-deps.mjs && node ../../scripts/assert-version-honesty.mjs","prepare":"rm -rf dist tsconfig.tsbuildinfo && tsc","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"pnpm run build"},"_npmUser":{"name":"mike-divinci","email":"mike@divinci.ai"},"repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"12.0.2","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.3.0_1789533476513_0.17509393533097128","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@divinci-ai/trustbench-verifier","version":"0.4.0","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.4.0","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"2a5ab6a320153f5b0737fb3eff36063afda7007f","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.4.0.tgz","fileCount":43,"integrity":"sha512-ep7qM7FLby0v7GtwrGD+fHqfYiEEjCIASEI1RKGhlxXnTwAJKr+G4cGJlpyDFKevJWIIWGFEdTWvdVqymb7nVA==","signatures":[{"sig":"MEUCIQD/61iU4UYCMqJscbRK84zWOAoZ28EVuamPto0GNbWaxAIgNvOZI/JGlq7EErnaidK9b/GmtdyJxV/sm7JBDksg/9I=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIHc87nJPkl0h9L3P8U1EsDGmmajTN2HEWjy1QmPyx/MrAiEAyLFquujFmQTMHuea8lX09bljOtarm11x4Vs8hOGmZrU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":274355},"main":"./dist/index.js","_from":"file:divinci-ai-trustbench-verifier-0.4.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"mike-divinci","email":"mike@divinci.ai"},"_resolved":"/private/var/folders/q4/pl30pmhs0qn8m30_d_pby9_40000gn/T/c7b291b7cf14e35b21ab4d968f1ae982/divinci-ai-trustbench-verifier-0.4.0.tgz","_integrity":"sha512-ep7qM7FLby0v7GtwrGD+fHqfYiEEjCIASEI1RKGhlxXnTwAJKr+G4cGJlpyDFKevJWIIWGFEdTWvdVqymb7nVA==","repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"12.0.2","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.4.0_1789969111224_0.8192454679370256","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@divinci-ai/trustbench-verifier","version":"0.5.0","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","_id":"@divinci-ai/trustbench-verifier@0.5.0","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"homepage":"https://app.divinci.app/trust","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"4a9b7cc39f31791bb3f2d33361b9fe7801bf3f7d","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.5.0.tgz","fileCount":43,"integrity":"sha512-6UaBk5lchn4/WRjkatSRhcKV85NV2uN4vrRrO79zEgXAaWCVOuPMpVrqAxVmX27vstKnojqVQ0o5BfVX5feKhg==","signatures":[{"sig":"MEUCIBDrwzRkvhDLodUa4txSozugO3lzm28maGoi1E3O5gdpAiEAsU2xVfiDf2xRKI99oX4xb8DUpjAO3R/QFBP2gTAGdZI=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEQCIA7turNvXQQfUieYCGtbk5WLNFGg+6Hs917Kg/mBX+e6AiAudk/Mv041Eciqwd44sQ4Ev6tJCPH/dmbLLnAVkiQXGw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":282516},"main":"./dist/index.js","_from":"file:divinci-ai-trustbench-verifier-0.5.0.tgz","types":"./dist/index.d.ts","module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage"},"_npmUser":{"name":"mike-divinci","email":"mike@divinci.ai"},"_resolved":"/private/var/folders/q4/pl30pmhs0qn8m30_d_pby9_40000gn/T/6831d44aeeac701378d408613685ef5c/divinci-ai-trustbench-verifier-0.5.0.tgz","_integrity":"sha512-6UaBk5lchn4/WRjkatSRhcKV85NV2uN4vrRrO79zEgXAaWCVOuPMpVrqAxVmX27vstKnojqVQ0o5BfVX5feKhg==","repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"12.0.2","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"tmp":"tmp/trustbench-verifier_0.5.0_1790325566620_0.5041328613094429","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"_id":"@divinci-ai/trustbench-verifier@0.6.0","bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"dist":{"shasum":"8158e5070b3d39a75f04421ace1ab00bfcf80df4","tarball":"https://registry.npmjs.org/@divinci-ai/trustbench-verifier/-/trustbench-verifier-0.6.0.tgz","fileCount":47,"integrity":"sha512-p16LFMBrLVu0yNud8Te/DYY2/By54BbDnMFiAVoUWFUohV/RhDtH3ISqzdUoExLn9l1raPDqJgpPQWPmVJtWdQ==","signatures":[{"sig":"MEYCIQDehTGtoq2el7/e9oQ9Lx9Qi1qg/wy5TDFIK+x5/qwjwwIhAKZgo6OPyycQFmrpWBCWKEJ8fFIYx4JHq12Fjbo98I7M","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQCrPSd2fTt/eEEjYyTdOxJ/i5mN5widwk+/6r71yT9YRQIhAJ/1URFhIz8pd578m0IYcY6lOye/VmaF997vgK155FLV"}],"unpackedSize":306379},"main":"./dist/index.js","name":"@divinci-ai/trustbench-verifier","types":"./dist/index.d.ts","author":{"name":"Divinci AI","email":"engineering@divinci.app"},"module":"./dist/index.js","engines":{"node":">=18.0.0"},"exports":{".":{"types":"./dist/index.d.ts","default":"./dist/index.js"}},"license":"MIT","scripts":{"test":"vitest run","build":"tsc","clean":"rm -rf dist tsconfig.tsbuildinfo","prepack":"node ../../scripts/assert-packed-deps.mjs && node ../../scripts/assert-version-honesty.mjs","prepare":"rm -rf dist tsconfig.tsbuildinfo && tsc","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","prepublishOnly":"pnpm run build"},"version":"0.6.0","_npmUser":{"name":"mike-divinci","email":"mike@divinci.ai"},"homepage":"https://app.divinci.app/trust","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"_npmVersion":"12.0.2","description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","directories":{},"maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"sideEffects":false,"_nodeVersion":"22.23.1","dependencies":{"zod":"^3.25.76","@noble/ed25519":"^2.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.3","@types/node":"^22.19.10","@vitest/coverage-v8":"^3.2.4"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/trustbench-verifier_0.6.0_1790852611060_0.7963335340587989"}}},"time":{"created":"2026-05-22T07:58:41.074Z","modified":"2026-10-01T11:03:31.391Z","0.1.0":"2026-05-22T07:58:41.306Z","0.1.1":"2026-08-19T12:11:14.311Z","0.2.0":"2026-09-06T09:22:43.518Z","0.3.0":"2026-09-16T04:37:56.669Z","0.4.0":"2026-09-21T05:38:31.310Z","0.5.0":"2026-09-25T08:39:26.705Z","0.6.0":"2026-10-01T11:03:31.151Z"},"bugs":{"url":"https://github.com/Divinci-AI/sdk/issues"},"author":{"name":"Divinci AI","email":"engineering@divinci.app"},"license":"MIT","homepage":"https://app.divinci.app/trust","keywords":["trustbench","divinci","ai","evaluation","attestation","ed25519","verifier","benchmark"],"repository":{"url":"git+https://github.com/Divinci-AI/sdk.git","type":"git"},"description":"Verify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node, Workers, and Deno.","maintainers":[{"name":"mike-divinci","email":"mike@divinci.ai"}],"readme":"# @divinci-ai/trustbench-verifier\n\nVerify TrustBench attested benchmark run manifests. Pure TypeScript, MIT-licensed, no Divinci-internal dependencies — works in browsers, Node ≥18, Cloudflare Workers, and Deno.\n\n## Install\n\n```bash\nnpm install @divinci-ai/trustbench-verifier\n# or\npnpm add @divinci-ai/trustbench-verifier\n```\n\n## Quick start\n\n```ts\nimport { verify } from \"@divinci-ai/trustbench-verifier\";\n\n// Fetch a signed manifest (from R2, an HTTP endpoint, or a local file)\nconst manifest = await fetch(\"https://app.divinci.app/v1/trustbench/runs/tr_x\")\n  .then(r => r.json());\n\n// Verify it (default: fetches well-known platform keys)\nconst result = await verify(manifest);\n\nif (result.verified) {\n  console.log(\"Verified by\", result.signedBy.keyId);\n} else {\n  console.error(\"Failed:\", result.errors);\n}\n```\n\n## Verifying outputs and benchmark content\n\nTo check that the outputs file and benchmark spec haven't been tampered with, pass them in:\n\n```ts\nconst outputs = await fetch(manifest.results.outputsR2Key).then(r => r.text());\nconst benchmarkContent = await loadBenchmarkSpec(manifest.benchmark.id);\n\nconst result = await verify(manifest, {\n  outputs,\n  benchmarkContent,\n});\n\nconsole.log({\n  verified: result.verified,\n  signatureValid: result.signatureValid,\n  outputsHashMatches: result.outputsHashMatches,\n  benchmarkContentHashMatches: result.benchmarkContentHashMatches,\n});\n```\n\n## Air-gapped / custom key resolution\n\nDon't want to make an outbound HTTPS call to fetch the well-known? Pass a custom resolver:\n\n```ts\nconst knownKeys = new Map<string, Uint8Array>([\n  [\"tbp-2026-04-26-001\", base64ToBytes(MY_LOCAL_PUB_KEY)],\n]);\n\nconst result = await verify(manifest, {\n  keyResolver: async (keyId) => knownKeys.get(keyId) ?? null,\n});\n```\n\n## Strict mode\n\nBy default, warnings (deprecated key still serving, etc.) don't fail verification. Pass `strict: true` to make them fail:\n\n```ts\nconst result = await verify(manifest, { strict: true });\n```\n\n## What `verify()` checks\n\nA run is `verified: true` only if all of:\n\n1. The manifest passes JSON-Schema-style validation against `TrustRunManifestV1`.\n2. The keyId in `signatures[0]` resolves to a known platform public key (from the well-known registry, or the supplied `keyResolver`).\n3. The manifest's claimed `publicKey` matches what the registry says — protects against a malicious manifest claiming a different keyId than it was actually signed with.\n4. Ed25519-verifying the signature against `sha256(canonicalJSON(body_without_signatures))` succeeds.\n5. (When `outputs` is provided) `sha256(outputs)` matches `manifest.results.outputsHash`.\n6. (When `benchmarkContent` is provided) `sha256(benchmarkContent)` matches `manifest.benchmark.contentHash`.\n7. `results.provenance.outputsR2Key`, when present, matches `results.outputsR2Key` — a signed manifest must not cite evidence other than the artifact it hashes.\n8. (When `strict: true`) no warnings present.\n\nThe function never throws on a verification failure — it returns a structured `VerifyResult` with errors and warnings. It DOES throw on operational failures (no `crypto.subtle` in the runtime, no `fetch` and no `fetchImpl`, etc.).\n\n## Signed ≠ measured: `result.scoreProvenance`\n\nA valid signature attests that Divinci **signed** the document. It does not\nattest that the number inside it was **measured**. Those are different claims,\nand until `results.provenance` existed a manifest carried only the first.\n\n`verify()` returns the signed provenance block on `result.scoreProvenance`:\n\n| `sourceKind` | meaning |\n|---|---|\n| `measured` | the evaluator execution named in `evaluator.invocationId` invoked the model under test and scored its actual replies |\n| `republished` | the score was computed by an earlier run (see `upstreamRef`), and this manifest only signs it |\n| `stub` | the score is **fabricated**; the model was never called |\n\n`scoreProvenance: null` means the manifest predates the field and therefore\nsays nothing either way. **Treat `null` as unknown provenance, never as\nmeasured.** Each of `null`, `stub` and `republished` raises a warning, so\n`strict: true` refuses all three in one flag:\n\n```ts\nconst r = await verify(manifest, { strict: true });\nif (r.verified && r.scoreProvenance?.sourceKind === \"measured\") {\n  // this number was measured, by the execution the manifest names\n}\n```\n\nThe platform signer refuses to mint a manifest without a provenance block, one\nwhose declaration contradicts itself (a `stub` claiming it called the model), or\na `stub` under a production key at all. So the guarantee is enforced where\nmanifests are created; this package is how you check it without trusting us.\n\n## Manifest schema\n\nDocumented at: `https://app.divinci.app/.well-known/trustbench/schemas/trustrun-v1.json`\n\nThe `TrustRunManifestV1` Zod schema is exported from this package and is the source of truth for the public-facing manifest shape.\n\n## License\n\nMIT.\n","readmeFilename":"README.md"}