# Claims review — 0.2.34

- base: v0.2.33
- head: 0198ccf
- surface: sha256:e80fad84574da3554959e855d5e9cb4db1a32b9e4cc3f58f3dd87db369dad5c3
- verdict: pass
- reviewer: Claude (Opus 5), then an independent pass by Codex and one by Cursor
  before the version was pushed

Four surfaces changed: `docs/PRIOR-ART.md`, `README.md`, `CHANGELOG.md`,
`docs/security/NPM-PROVENANCE.md`. The release is itself a claims correction, so
most of the diff removes reach. The findings below are ordered by who found them,
because that ordering is the useful part of this record: **the first pass missed
the two that mattered, and both were found by readers who had not written the
text.**

## Findings

### 1. docs/PRIOR-ART.md — a design section scored as behaviour

- Claim: the Vaara row read **"Yes — the only other one here"** on coverage
  reconciliation, and the file, `README.md` and `CHANGELOG.md` all said that
  project *reconciles*.
- Mechanism: `docs/design/credential-broker-spec.md` §D at `befdced`, which
  designs a join of used credentials to receipts on `attestationDigest`.
- Why it falls short: §D is a design document. A search of that tree for a
  collector of used credentials, the join, a CLI or a test found none, and
  `src/vaara/credential/gateway.py` refers that residual to the design document
  rather than to code. Every other row in the table is scored on what a project
  is found doing. Scoring a specification as behaviour is the confusion this
  file's own column definitions warn about — *"not that the log records that it
  happened, but that the value never left"* — committed by the person who wrote
  them, in the row that changed the headline claim.
- Disposition: rescored **"Specified, not found implemented"** in `0198ccf`,
  with the first scoring left visible on the page rather than quietly replaced.
  `README.md` and `CHANGELOG.md` narrowed to match. The retired phrasings are
  named so they are not requoted: *"nobody else reconciles"*, *"none of the ten
  has the third column"*.
- **Found by: Codex.** Not by the first pass, which had read the same section and
  taken it at its word.

### 2. docs/PRIOR-ART.md — the summary paragraph contradicted the new row

- Claim: *"Two projects do both — Microsoft's toolkit and h33.ai — and neither
  does the third."*
- Mechanism: the table directly above it.
- Why it falls short: the sentence sat unchanged three lines under a row that
  had just been scored **Yes** on the third column. The paragraph immediately
  after it was rewritten in the same edit; this one was not. A reader opening the
  file from the post's first comment meets the contradiction before the
  correction.
- Disposition: rewritten in `0198ccf` to name three projects and say none was
  found running the third.
- **Found by: Cursor.** The first pass edited the paragraph below it and did not
  re-read the paragraph above.

### 3. docs/security/NPM-PROVENANCE.md — a limitation that expired the same day

- Claim: *"Those steps have not run yet — 0.2.34 is the first release that will
  execute them"*, and *"every version published so far has only npm's
  attestation"*.
- Mechanism: the workflow runs and the release pages.
- Why it falls short: both were true when written and false a few hours later.
  The `artefacts` mode added in #32 was dispatched against 0.2.33 (runs
  `32295097847`, `32295276511`), which verified the registry tarball, produced a
  GitHub attestation and created that release. `v0.2.33` now carries
  `conarium-ai-core-0.2.33.tgz` and `.tgz.intoto.jsonl`, and
  `gh attestation verify` returns 0 for it.
- Disposition: replaced in `0198ccf` with what has actually run, including that
  0.2.33 carries no bill of materials because that step is skipped in artefacts
  mode, and that the full publish path has still not run.
- **Found by: Codex.** Worth noting how it expired: this was a self-correction in
  the first pass (finding 5 below), written carefully, and then invalidated by
  our own action. A sentence about what has not happened yet has a shelf life.

### 4. CHANGELOG.md — three assets described as an existing state

- Claim: *"releases now carry: the published tarball, a CycloneDX bill of
  materials, and a build attestation"*.
- Mechanism: `publish.yml` produces the SBOM only in `publish` mode and uploads
  only the assets that exist.
- Why it falls short: no release carries all three. 0.2.33 carries two; 0.2.34
  was not on npm when this was written.
- Disposition: narrowed to what the publish path is *configured* to produce, with
  0.2.33's actual contents named. The neighbouring *"stops one version short …
  again"* was in the present tense for a past event and is now *"had stopped"*.
- **Found by: Codex.**

### 5. docs/security/NPM-PROVENANCE.md — an artefact described before it existed

- Claim: *"From 0.2.34 the publish workflow attaches three files to the GitHub
  release"*, over a table of them.
- Mechanism: the steps added in #28, which had never executed.
- Why it falls short: it described an intention as an artefact — the defect
  0.2.33 was published to fix, with the sign reversed.
- Disposition: reworded in `d816ce1`, then superseded by finding 3 once the steps
  actually ran.
- **Found by: the first pass**, which is recorded here mainly to be honest about
  its hit rate: it caught the claim it had just written, and missed the two that
  came from reading someone else's code and re-reading its own file.

### 6. docs/PRIOR-ART.md — a competitor's mechanism overstated

- Claim: the Microsoft row read *"Ed25519, **Merkle-chained**"*.
- Mechanism: their own tutorial, which describes a linear `parent_receipt_hash`.
- Why it falls short: it is wrong, and wrong in their favour. A comparison table
  that inflates a competitor is no more trustworthy than one that inflates its
  author; both mean the rows were not checked.
- Disposition: corrected in `0198ccf`, with the previous wording named.
- **Found by: Cursor.**

## Verification note

Vaara's contiguity tests were run during the first pass —
`PYTHONPATH=src python -m pytest tests/credential/test_contiguity.py` → 18
passed, at `befdced`. Codex could not reproduce that (`rfc8785` missing, no
package import environment) and correctly flagged that the claim had no command
recorded against it. The command and result are now in `docs/PRIOR-ART.md` beside
the claim rather than only in a session transcript.
