{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "$ref": "#/definitions/Lockfile",
  "definitions": {
    "SourceSubPath": { "type": "string", "minLength": 1 },
    "Handle": {
      "type": "string",
      "pattern": "^@[a-z0-9_](?:[a-z0-9_-]*[a-z0-9_])?$",
      "title": "Handle",
      "description": "A unique username or organization name starting with @, like @my-org.",
      "examples": ["@my-org", "@username"]
    },
    "ExtensionName": {
      "type": "string",
      "minLength": 1,
      "pattern": "^[a-z0-9](?:[a-z0-9-]{0,62}[a-z0-9])?$",
      "title": "Extension Name",
      "description": "The name of an extension — lowercase letters, numbers, and hyphens (e.g. my-skill).",
      "examples": ["my-skill", "code-review", "prettier"]
    },
    "TreeIntegrity": { "type": "string" },
    "Version": {
      "type": "string",
      "pattern": "^(0|[1-9]\\d*)\\.(0|[1-9]\\d*)\\.(0|[1-9]\\d*)(?:-((?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\\.(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\\+([0-9a-zA-Z-]+(?:\\.[0-9a-zA-Z-]+)*))?$",
      "title": "Version",
      "description": "A semver version like 1.0.0. Ranges are not allowed here.",
      "examples": ["1.0.0", "2.3.1", "0.1.0-beta.1"]
    },
    "ExtensionFqn": {
      "type": "string",
      "pattern": "^(@[a-z0-9_](?:[a-z0-9_-]*[a-z0-9_])?)\\/(skills|mcps|subagents|rules|hooks|knowledge|packs)\\/([a-z0-9](?:[a-z0-9-]{0,62}[a-z0-9])?)$",
      "title": "Extension FQN",
      "description": "Canonical extension identifier in @owner/<type>s/<name> form.",
      "examples": ["@acme/skills/code-review", "@my-org/rules/typescript"]
    },
    "PackLockEntry": {
      "anyOf": [
        {
          "type": "object",
          "properties": {
            "source": {
              "type": "object",
              "properties": {
                "type": { "type": "string", "enum": ["git"] },
                "url": { "type": "string" },
                "path": {
                  "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                },
                "revision": { "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }] }
              },
              "required": ["type", "url"],
              "additionalProperties": false
            },
            "identity": {
              "type": "object",
              "properties": {
                "owner": { "$ref": "#/definitions/Handle" },
                "name": { "$ref": "#/definitions/ExtensionName" }
              },
              "required": ["owner", "name"],
              "additionalProperties": false
            },
            "resolved": {
              "type": "object",
              "properties": {
                "commit": { "type": "string", "minLength": 1 },
                "tree": { "type": "string", "minLength": 1 }
              },
              "required": ["commit", "tree"],
              "additionalProperties": false
            },
            "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" },
            "manifestVersion": { "$ref": "#/definitions/Version" },
            "manifestContentIdentity": {
              "type": "string",
              "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
            },
            "members": { "type": "array", "items": { "$ref": "#/definitions/ExtensionFqn" } }
          },
          "required": [
            "source",
            "identity",
            "resolved",
            "treeIntegrity",
            "manifestVersion",
            "manifestContentIdentity",
            "members"
          ],
          "additionalProperties": false
        },
        {
          "type": "object",
          "properties": {
            "source": {
              "type": "object",
              "properties": {
                "type": { "type": "string", "enum": ["registry"] },
                "url": { "type": "string" }
              },
              "required": ["type", "url"],
              "additionalProperties": false
            },
            "identity": {
              "type": "object",
              "properties": {
                "owner": { "$ref": "#/definitions/Handle" },
                "name": { "$ref": "#/definitions/ExtensionName" }
              },
              "required": ["owner", "name"],
              "additionalProperties": false
            },
            "resolved": {
              "type": "object",
              "properties": {
                "version": { "$ref": "#/definitions/Version" },
                "integrity": {
                  "type": "string",
                  "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                },
                "publisherBindingId": { "type": "string", "minLength": 1 }
              },
              "required": ["version", "integrity", "publisherBindingId"],
              "additionalProperties": false
            },
            "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" },
            "manifestVersion": { "$ref": "#/definitions/Version" },
            "manifestContentIdentity": {
              "type": "string",
              "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
            },
            "members": { "type": "array", "items": { "$ref": "#/definitions/ExtensionFqn" } }
          },
          "required": [
            "source",
            "identity",
            "resolved",
            "treeIntegrity",
            "manifestVersion",
            "manifestContentIdentity",
            "members"
          ],
          "additionalProperties": false
        },
        {
          "type": "object",
          "properties": {
            "source": {
              "type": "object",
              "properties": {
                "type": { "type": "string", "enum": ["path"] },
                "path": { "type": "string" }
              },
              "required": ["type", "path"],
              "additionalProperties": false
            },
            "identity": {
              "type": "object",
              "properties": {
                "owner": { "$ref": "#/definitions/Handle" },
                "name": { "$ref": "#/definitions/ExtensionName" }
              },
              "required": ["owner", "name"],
              "additionalProperties": false
            },
            "resolved": {
              "type": "object",
              "properties": {
                "tree": {
                  "type": "string",
                  "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                }
              },
              "required": ["tree"],
              "additionalProperties": false
            },
            "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" },
            "manifestVersion": { "$ref": "#/definitions/Version" },
            "manifestContentIdentity": {
              "type": "string",
              "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
            },
            "members": { "type": "array", "items": { "$ref": "#/definitions/ExtensionFqn" } }
          },
          "required": [
            "source",
            "identity",
            "resolved",
            "treeIntegrity",
            "manifestVersion",
            "manifestContentIdentity",
            "members"
          ],
          "additionalProperties": false
        }
      ],
      "title": "Pack Lock Entry",
      "description": "Accepted immutable resolution and declared members for a Pack."
    },
    "Lockfile": {
      "type": "object",
      "properties": {
        "lockfileVersion": {
          "type": "number",
          "enum": [8],
          "description": "Lockfile schema version.",
          "default": 8
        },
        "skills": {
          "type": "object",
          "additionalProperties": {
            "anyOf": [
              {
                "type": "object",
                "properties": {
                  "source": {
                    "type": "object",
                    "properties": {
                      "type": { "type": "string", "enum": ["git"] },
                      "url": { "type": "string" },
                      "path": {
                        "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                      },
                      "revision": {
                        "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                      }
                    },
                    "required": ["type", "url"],
                    "additionalProperties": false
                  },
                  "identity": {
                    "type": "object",
                    "properties": {
                      "owner": {
                        "anyOf": [{ "$ref": "#/definitions/Handle" }, { "type": "null" }]
                      },
                      "name": { "$ref": "#/definitions/ExtensionName" }
                    },
                    "required": ["name"],
                    "additionalProperties": false
                  },
                  "resolved": {
                    "type": "object",
                    "properties": {
                      "commit": { "type": "string", "minLength": 1 },
                      "tree": { "type": "string", "minLength": 1 }
                    },
                    "required": ["commit", "tree"],
                    "additionalProperties": false
                  },
                  "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                },
                "required": ["source", "identity", "resolved", "treeIntegrity"],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "source": {
                    "type": "object",
                    "properties": {
                      "type": { "type": "string", "enum": ["registry"] },
                      "url": { "type": "string" }
                    },
                    "required": ["type", "url"],
                    "additionalProperties": false
                  },
                  "identity": {
                    "type": "object",
                    "properties": {
                      "owner": { "$ref": "#/definitions/Handle" },
                      "name": { "$ref": "#/definitions/ExtensionName" }
                    },
                    "required": ["owner", "name"],
                    "additionalProperties": false
                  },
                  "resolved": {
                    "type": "object",
                    "properties": {
                      "version": { "$ref": "#/definitions/Version" },
                      "integrity": {
                        "type": "string",
                        "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                      },
                      "publisherBindingId": { "type": "string", "minLength": 1 }
                    },
                    "required": ["version", "integrity", "publisherBindingId"],
                    "additionalProperties": false
                  },
                  "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                },
                "required": ["source", "identity", "resolved", "treeIntegrity"],
                "additionalProperties": false
              },
              {
                "type": "object",
                "properties": {
                  "source": {
                    "type": "object",
                    "properties": {
                      "type": { "type": "string", "enum": ["path"] },
                      "path": { "type": "string" }
                    },
                    "required": ["type", "path"],
                    "additionalProperties": false
                  },
                  "identity": {
                    "type": "object",
                    "properties": {
                      "owner": {
                        "anyOf": [{ "$ref": "#/definitions/Handle" }, { "type": "null" }]
                      },
                      "name": { "$ref": "#/definitions/ExtensionName" }
                    },
                    "required": ["name"],
                    "additionalProperties": false
                  },
                  "resolved": {
                    "type": "object",
                    "properties": {
                      "tree": {
                        "type": "string",
                        "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                      }
                    },
                    "required": ["tree"],
                    "additionalProperties": false
                  },
                  "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                },
                "required": ["source", "identity", "resolved", "treeIntegrity"],
                "additionalProperties": false
              }
            ]
          }
        },
        "subagents": {
          "anyOf": [
            {
              "type": "object",
              "additionalProperties": {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["git"] },
                          "url": { "type": "string" },
                          "path": {
                            "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                          },
                          "revision": {
                            "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                          }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "commit": { "type": "string", "minLength": 1 },
                          "tree": { "type": "string", "minLength": 1 }
                        },
                        "required": ["commit", "tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["registry"] },
                          "url": { "type": "string" }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "version": { "$ref": "#/definitions/Version" },
                          "integrity": {
                            "type": "string",
                            "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                          },
                          "publisherBindingId": { "type": "string", "minLength": 1 }
                        },
                        "required": ["version", "integrity", "publisherBindingId"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["path"] },
                          "path": { "type": "string" }
                        },
                        "required": ["type", "path"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "tree": {
                            "type": "string",
                            "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                          }
                        },
                        "required": ["tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  }
                ]
              }
            },
            { "type": "null" }
          ]
        },
        "mcpServers": {
          "anyOf": [
            {
              "type": "object",
              "additionalProperties": {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["git"] },
                          "url": { "type": "string" },
                          "path": {
                            "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                          },
                          "revision": {
                            "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                          }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "commit": { "type": "string", "minLength": 1 },
                          "tree": { "type": "string", "minLength": 1 }
                        },
                        "required": ["commit", "tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["registry"] },
                          "url": { "type": "string" }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "version": { "$ref": "#/definitions/Version" },
                          "integrity": {
                            "type": "string",
                            "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                          },
                          "publisherBindingId": { "type": "string", "minLength": 1 }
                        },
                        "required": ["version", "integrity", "publisherBindingId"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["path"] },
                          "path": { "type": "string" }
                        },
                        "required": ["type", "path"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "tree": {
                            "type": "string",
                            "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                          }
                        },
                        "required": ["tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  }
                ]
              }
            },
            { "type": "null" }
          ]
        },
        "rules": {
          "anyOf": [
            {
              "type": "object",
              "additionalProperties": {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["git"] },
                          "url": { "type": "string" },
                          "path": {
                            "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                          },
                          "revision": {
                            "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                          }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "commit": { "type": "string", "minLength": 1 },
                          "tree": { "type": "string", "minLength": 1 }
                        },
                        "required": ["commit", "tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["registry"] },
                          "url": { "type": "string" }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "version": { "$ref": "#/definitions/Version" },
                          "integrity": {
                            "type": "string",
                            "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                          },
                          "publisherBindingId": { "type": "string", "minLength": 1 }
                        },
                        "required": ["version", "integrity", "publisherBindingId"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["path"] },
                          "path": { "type": "string" }
                        },
                        "required": ["type", "path"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "tree": {
                            "type": "string",
                            "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                          }
                        },
                        "required": ["tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  }
                ]
              }
            },
            { "type": "null" }
          ]
        },
        "hooks": {
          "anyOf": [
            {
              "type": "object",
              "additionalProperties": {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["git"] },
                          "url": { "type": "string" },
                          "path": {
                            "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                          },
                          "revision": {
                            "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                          }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "commit": { "type": "string", "minLength": 1 },
                          "tree": { "type": "string", "minLength": 1 }
                        },
                        "required": ["commit", "tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["registry"] },
                          "url": { "type": "string" }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "version": { "$ref": "#/definitions/Version" },
                          "integrity": {
                            "type": "string",
                            "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                          },
                          "publisherBindingId": { "type": "string", "minLength": 1 }
                        },
                        "required": ["version", "integrity", "publisherBindingId"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["path"] },
                          "path": { "type": "string" }
                        },
                        "required": ["type", "path"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "tree": {
                            "type": "string",
                            "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                          }
                        },
                        "required": ["tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  }
                ]
              }
            },
            { "type": "null" }
          ]
        },
        "knowledge": {
          "anyOf": [
            {
              "type": "object",
              "additionalProperties": {
                "anyOf": [
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["git"] },
                          "url": { "type": "string" },
                          "path": {
                            "anyOf": [{ "$ref": "#/definitions/SourceSubPath" }, { "type": "null" }]
                          },
                          "revision": {
                            "anyOf": [{ "type": "string", "minLength": 1 }, { "type": "null" }]
                          }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "commit": { "type": "string", "minLength": 1 },
                          "tree": { "type": "string", "minLength": 1 }
                        },
                        "required": ["commit", "tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["registry"] },
                          "url": { "type": "string" }
                        },
                        "required": ["type", "url"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "version": { "$ref": "#/definitions/Version" },
                          "integrity": {
                            "type": "string",
                            "description": "SRI sha512 of the published archive, verified against downloaded bytes before extraction. The supply-chain guarantee for registry installs; never compared against installed files on disk."
                          },
                          "publisherBindingId": { "type": "string", "minLength": 1 }
                        },
                        "required": ["version", "integrity", "publisherBindingId"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  },
                  {
                    "type": "object",
                    "properties": {
                      "source": {
                        "type": "object",
                        "properties": {
                          "type": { "type": "string", "enum": ["path"] },
                          "path": { "type": "string" }
                        },
                        "required": ["type", "path"],
                        "additionalProperties": false
                      },
                      "identity": {
                        "type": "object",
                        "properties": {
                          "owner": { "$ref": "#/definitions/Handle" },
                          "name": { "$ref": "#/definitions/ExtensionName" }
                        },
                        "required": ["owner", "name"],
                        "additionalProperties": false
                      },
                      "resolved": {
                        "type": "object",
                        "properties": {
                          "tree": {
                            "type": "string",
                            "description": "Advisory SHA-256 change-detection marker of canonical content at install time. Not a tamper guarantee: installed content is workspace-owned and may be rewritten by content-preserving tools after install."
                          }
                        },
                        "required": ["tree"],
                        "additionalProperties": false
                      },
                      "treeIntegrity": { "$ref": "#/definitions/TreeIntegrity" }
                    },
                    "required": ["source", "identity", "resolved", "treeIntegrity"],
                    "additionalProperties": false
                  }
                ]
              }
            },
            { "type": "null" }
          ]
        },
        "packs": {
          "anyOf": [
            { "type": "object", "additionalProperties": { "$ref": "#/definitions/PackLockEntry" } },
            { "type": "null" }
          ]
        }
      },
      "required": ["lockfileVersion", "skills"],
      "additionalProperties": false,
      "title": "AXM Lockfile",
      "description": "Accepted immutable external source resolutions and provenance. Desired state and projection ownership are authoritative elsewhere."
    }
  }
}
