From 67755d71a8ee8eed4faf6d46ae9656a0dc3e79eb Mon Sep 17 00:00:00 2001 From: CueCrux-Myles Date: Wed, 5 Aug 2026 13:45:42 +0100 Subject: [PATCH 1/2] Give the README a wordmark and two diagrams MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The README argued for reproducibility in prose alone. Two of its claims are structural and read better as pictures: that every pin is resolved before a single rule runs, and that the three tiers never merge. Adds four hand-authored SVGs under docs/Images/readme/, following the visual grammar already established by the Crux daemon README so the two repositories read as siblings — one monospace stack with no webfonts, since GitHub sanitises SVG and will not fetch one; a dark panel with corner washes; glass panes with accent bars; and the same accent palette throughout. probecrux-{light,dark}.svg the wordmark. The CRUX half is Crux's own glyph geometry translated rather than redrawn, so the two marks are identical where they overlap; PROBE is constructed to the same metrics (699 cap height, 179-unit stem). how-it-works.svg acquire, pin, scan, evaluate, with the deterministic, heuristic and advisory tiers drawn as visibly separate panes. receipt.svg what the receipt attests set against what it does not, plus the project and operator key classes. Both canonical quotes are reproduced verbatim in receipt.svg and left in the prose as well, so neither the manifest wording nor a text search for it depends on an image. No existing wording changed. The status and pre-1.0 rule-identifier warnings keep their position directly beneath the hero. Co-Authored-By: Claude Opus 5 (1M context) --- README.md | 45 ++++++++++++- docs/Images/readme/CueCrux-Arc-Loop-White.png | Bin 0 -> 19462 bytes docs/Images/readme/CueCrux-Arc-Loop.png | Bin 0 -> 20152 bytes docs/Images/readme/how-it-works.svg | 59 ++++++++++++++++++ docs/Images/readme/probecrux-dark.svg | 11 ++++ docs/Images/readme/probecrux-light.svg | 11 ++++ docs/Images/readme/receipt.svg | 34 ++++++++++ 7 files changed, 158 insertions(+), 2 deletions(-) create mode 100644 docs/Images/readme/CueCrux-Arc-Loop-White.png create mode 100644 docs/Images/readme/CueCrux-Arc-Loop.png create mode 100644 docs/Images/readme/how-it-works.svg create mode 100644 docs/Images/readme/probecrux-dark.svg create mode 100644 docs/Images/readme/probecrux-light.svg create mode 100644 docs/Images/readme/receipt.svg diff --git a/README.md b/README.md index 755117e..c17c422 100644 --- a/README.md +++ b/README.md @@ -1,6 +1,31 @@ -# ProbeCrux +
-A Rust workspace audit that emits a signed, replayable receipt alongside its findings. + + + CueCrux arc-loop mark + +

+ + + PROBECRUX + + +### Reproducibility is the product. + +**A Rust workspace audit that emits a signed, replayable receipt alongside its findings.** +Seventeen rules across three tiers, append-only identifiers, and a receipt that pins the +commit, the manifest hash, the advisory snapshot, the pattern set and the toolchain. +Nothing is fetched during a run. Verification is offline. + +[How it works](#how-it-works) · [The receipt](#what-the-receipt-attests) · +[Signing](#signing-whose-receipt-is-it) · [Rule set](#rule-set) · [Docs](#documentation) + +[![ci](https://github.com/CueCrux/ProbeCrux/actions/workflows/ci.yml/badge.svg)](https://github.com/CueCrux/ProbeCrux/actions/workflows/ci.yml) +[![manifest-hash](https://github.com/CueCrux/ProbeCrux/actions/workflows/manifest-hash.yml/badge.svg)](https://github.com/CueCrux/ProbeCrux/actions/workflows/manifest-hash.yml) +[![Licence: Apache-2.0](https://img.shields.io/badge/licence-Apache--2.0-blue)](LICENCE) +![Status: pre-release](https://img.shields.io/badge/status-pre--release-orange) + +
**Status: in development, not released.** The library crates exist and are tested. There is no published binary, no container image on any registry, and no receipt has been @@ -24,6 +49,19 @@ set version, and the toolchain. The rules live in [`probecrux.rules.yaml`](probecrux.rules.yaml). That file is the product; the runner is plumbing. +## How it works + +Every pin is resolved before a single rule runs. A receipt assembled from what a run +happened to use is a description; one assembled from what a run was told to use is a +constraint. The three tiers stay in separate sections all the way to the output, because +a blended total lets an unreproducible finding inherit the credibility of a reproducible +one. + +ProbeCrux pipeline: a repository and optional ref are acquired to a concrete commit SHA, then the manifest hash, advisory snapshot, pattern set, toolchain and build id are pinned before any rule runs; a single scan traversal builds the shared index, rules evaluate as pure functions over it, and findings land in three separate tiers — 14 deterministic, 2 heuristic, 1 advisory — emitted as findings.json, report.md and a signed receipt over an append-only rule manifest + +More detail: [`docs/architecture.md`](docs/architecture.md). + ## Aims **Reproducibility is the product.** Where reproducibility and coverage conflict, @@ -57,6 +95,9 @@ ProbeCrux reports findings for triage. It does not issue assurance. It is not an audit in any regulatory sense, it is not a legal opinion, and a passing run is not evidence that a codebase is safe. +What a ProbeCrux receipt attests — that these rules, at this version, were evaluated against this commit at this time and produced this findings set — set against what it does not attest: that the repository is secure, correct, fit for purpose or free of defects outside the scope of these rules. Two key classes are shown: project, the published key that gives tamper-evidence but names no party, and operator, your own key, which binds the findings to whoever controls it + ## Why a receipt at all Retroactive provenance is not a thing. A report tells you what a tool found; it does diff --git a/docs/Images/readme/CueCrux-Arc-Loop-White.png b/docs/Images/readme/CueCrux-Arc-Loop-White.png new file mode 100644 index 0000000000000000000000000000000000000000..59fce78a38d3127fa01afcac5a1506bd694736e4 GIT binary patch literal 19462 zcmeIacU;rUw01!>YxF62NQ-#K<&`;OifZjh6Jo1_p&0OE0%}N=pU>7)!h9+H2SoEU>48 ztj|PZozFP9_@4>(Hwch6HIX!mGXwxavC+PgaiJk$QHF8G(!b#vf}dH#>e78bi_>L4Zc4b(LCbTqW}R3x=DG!4`>km{P+sv4Sx8hVDh z`jUVDCk=Ls48R#;ERX)Z7x>Ls`gC+O!BAa2Ha1o*R$DDRGEiO9zyQF|QrFT_1v6Bm z;=`hS<5a_`kes3P&uZ|7DhGN5_qrhCvf94WShewA;oeuvGK>zdkf7k%9 z*53Y~J^o!>LPP)AA}aa_5s>jWL;l^_Q7-WWtU3l86&@4mk3B*JXv+MHny6?D_P_J< zzpxxk|Gk)CXc39^jSi1=2@enXmy{j5W+7d)G!1n$4YhRsH4A82fN!+#|7u=< zzacI>GSnBaCn(f65UWlI3zU}phv|kE;UVFXU^{@0_P-rRTUaQL^|2-V^@9^WlwDaHVV^3oN(0^Yo{@OSy92Xty8;Law1Z?|HHBS9M#5+8U zh>iR=m=k;>eSy=$Mn)M+<08XDCI3+t$>?xNUjiW{$lsSmvpO*>;BUw9kCdeU!+oNB ziT`Wv_yzcC_#6270d3LKRMj`o@l`dzA(5&E{@WtxsXybrF`D!BlRB^sKeyV={{{E_(T6+GvSbuFT zeVop}u>7Cs_#e#r|7AM-|5LgDC!%I)!#}F=AM+~!8yWO(B>!)<>mL*(f9u)*GyDCg zdiG!QN`G~;S7-SRIc9%Y&1?<30a-}5j3Rm}rumLc%2|B1gf z(DTLlYxwG^`swQ;RgwNWSXEyw1ASE;f1uww0e*fseO;Cwv!I3l@A_Mo+xX3fe-oDc zYY4HaoMc*c3@O@5jG!T~ zWcCoLOZQ}laGmd3V*>-PRx0rcRm4YSL^c&DT(Zr`d72OH%1T;tH1ALfk>#F0%HW}! zE*svAV+(QUmZMgvP{=KQ13GJ553d&BO}LTg3Qim!MPKm?<1pbcva@>@F21=&){zmm zL5J#CQ|L$NhR=jjMg*~#`o;`}!YSFK$VUFpdU8Q!08mjFsXbV9KUd?e%BG zo9>hLR{~7Tu7sS>k~2P^iov{LjvZLTFl7DuDrRd9N+C<^9Z)07yB6F-F{z_cLkQ)RvykILSRtcs z>jfRK)Ua2sKhlT|$%{15&0HYLtcds-&&@PD$+|u^SEO>Er$K3gKD#0k2N))2Q@>Bc z8J@Jj4DSyP*|rFua*E3}1DZO&*y+jhfu?x;I4LScUGQ0?6Q zoOI{&;!WH?;%SqKEvM+@8MoFAynx?4InFh)$Lkn#Z|ooj&ktzGP?62riZ`9izBku= zp@}-5!jvSROU1lCxJG)K;`w~%B)-L)mPRs_SrW~s(7_HD+=ZIYH8mf_SG1;#XXNzs zz4WM@taY^csY9Q%=<*h$s*Rz&=D)ecDQCNg@l*|}!{{8vu>z@>g*vhHdR2YFwA;2d zz)vltozM8hR3_wRexJuN)TU|C;WIf(fG;hfnh|`{FUQO(Ihr`PxK^-!7TJ|#cZI4Y z5y(!sA7U&B>?nW2swD86q$Wa*DhW10!05W^`=LGLdh5`KmlUquS-BBS1>_ATpQnGz zDSNUeQ#Cfq+jhP{Fkgpfpa(7)G<=aHl-`=vc>#+lx+lPRLu;qIRzzXmSgU^Esv2~# zV*7=N4Y74~M~hQB^ib)8!ooIG?`s0Vvf15m>2+GOW$gq7VTlJCGzh;;x|6OfC^r-c zBgi?a7(c}nT}Z{?ANevwr!QHeR_?luFy<&>fz$QFXp54c?V{tV+CZG$O^ z$!+TK#FxsD9{3khiay#gw&}Zh$j<@Ab4dQCU0d7{%a1B?MLdb;nx03Ph3%z^lzh4N zr4QCGH5|w%88jZCcig-z6o-Q01d)|kcloOOB5WNHFDvnHa_bjmD3~O;)Xoh99aMT{_dU6= zx8LwYekwf6(PpUl*hJ)7j7l!%lsNYfIRaEOQZc3oENIA*&e|XG-FD$YYx=A1J|Mdq zq`9K2KYRtshyw6CP&rL?s}z8Zt9Uu3J9aNYOmj#TJ>$(bLF(e6`m0bd@fS0qKC1P= zrKzu$q=#M4Dx=a}gn6o5vYwK%VVCR9TPuBtV2IKAjvwRiahrpEPM?};CAnSs`9p8o zZfxv3ALBh+=Se&-SkVhvNoKSG4$JGAMNLyE*g6!4HL#Y(Mr)b6ZgxR4A{RnGlIxS$#n06L>$J z2$&|hDOKT$Scc!`-oB>51T`mx{jfBcI?RFdq(zCFLD4lkr5EOkef?UDawb1!;I16^ z%y}BoN61NZ+^|LeFr`~+V`t6!UO+hohvV9kBpe02of#I8$tpu^H~GrNQ~5nmW`)R*qj|f_%ee;peWcas z@FohmQ%Wpq-mpw`f5s~`x`yIBxlnh6HU)(NCKlb5%KGVX9bt*-M4D6Y8$z~{iCk3q zMmBxe9vCXO-g-gGN@3`T3@sK=sM~b8;BB&zL0V;Llyg=KPOTOih}6I6LUpCxNy&X^ zXM=};$#QF?2aK?=m=Qd~f_93LsYe#21JLeVKUA~qYKo6T^Vv=TEkp}N02n^(TepCA z?K%!~69OThXpewR!#gN#q~5|>&XcpmRvh+W@KNRSddHf+qa^h!NtBl9IEIPQjuqxI z@HL^jY>9C95`?AF%Vru6skIiMATr`uliB9rHE@13q_eL099n_nL=|fPg zc|$4`eBCozEFefbT7SjCCyL0AuDP6wv2TEEnGv~yIF6>A%@zxjUB4QvFl2e2w!q|n z%{u{UV+RmRzlhuDzEX`Fu6*mON|0Ld0c*Q~TQ8b3VtfGebi8=Qv#=O4!1|~GbjuQe z;|@*_PaMVpva26D)+oX`Itl^aPtde7Xe$e!Tz7>b_NbJzFX2*)Pfsuqv=-oB1}($7 zogNv`egV4QrqyS7PoV0-TxSo3yhV8*Gyuz1oTAUTT`6n-(tENyTA1L+8jFSe67B(G zmxC4Zp4lVuH@#_MDV(fbih(lmuB99cOuJe-Yr^>TL`xB^jVpJ#SWG$s3@$>ABa8Eq z-2BzbaSjbi) zYicts4JahW&0WDY-;_-_FwJo}l>Ou$qarY|g{~MrGUn*nK8D@`IUU|iifj3@~6_WDwH^=3_jG}-m6 zR1CHl_CvSSfO_U0H0yC|lbm8|aiq(mSl>dI_9bb!^3=5w3-TGD@_9i5EAB+D^-FFF zHW*lwq7}A99z{ActIN^`vaFSY>p}hL+YS%dI`R%PXK)&>*!i3=z6Y^4gnt2pM-|I06Zu< z7#kn_sJ{n(!{LlL;8R1E45f(A>X2)yH%%QT29$@4doEzp_x#8hbkLxfboM;Z(i1Pi z$Y3HPZA@xV@lHA)vH~z2T@Umbw@?SzN%@@O4-5`-$H1IgcmTSih`L}nbDXhAe~U(A zF0%&Ra}bBGN9bNdqZfDqQr;G{PT&$QHHkMNQ5R&XMw66^PiIuGq4&iqu}-y%2*S;SQ8MFZ)ZZL<;Brtd2IQh<;DQ~#?dB;COsC*zo}4)UTiQSHjUhI z&Mewd?h3j&x9VXELu!nBaaA{EgNj&Fo`5Oq%Ctv7=PNfJ0^G9f)<@8BMptEnF0#Hm z5+PMcvA@Ka1g=ez#Hdyv9vx+XK!7I^GPDrp7mXoTdH`li9~2vu5X*?kCCl~!E((bN z>An3S|4^HS&^s2iM@&e~v-h;Q-@5_6N_*DBZb$Bi1+$23c?|e)1&FvRj9m@5A@oAl zPvY|A_3LJRQT!{{nfx{M<34A9RGX1qq=AwN^c;dQG8YMT96-QOn#-l6O5rTDOvP8z_Wm4uHFH7Ip&9Wsj3pX z<|t4|BZwDp@#MihfD1TpB4po} zvJ`I?(4RhF2{;P=yo<>CEH8)Ftpm#ASqD3Pyq|Lz_$}G>%Uv8nTE7p2a*^gef63;T zyF!C{HWY+Fr{5-XjOMUFn>xe?pK7alV0xD~~rn z+P=xPhdZMOoSL%+;F9Rq2Zg(d23+o1eFN8>U!%OO#*A*Ud9n=pkF?Y}@BYHa^Vimw zH{O#=DT zs=gB3qe2PmrB0oF4C|F^nBpgh5zHgut}o2T5)TP)HQ3tPLdR_quT?)1bY~qUHX57heGjUgPhUKSZB`V(cO2ISL4sze^b4)7md%%;Lug8*dk?!J~toplA&|? ziwr3CC=g;Y2Ht4@Jh-%QZBRA$rvcI7o}!BZ4>sy220fsdVD-*I&h(hCF~J`&S!t{= z_s3QSrL+H3h6<(6_4!9x$}h3uKIx&Yfib8oHGmVsv$49?>FLJrI$%C#2czgCR$BLt zEAE7huUZ$^dD~wB38Z|L;_3Ngw?;jB@K^t~{DB6pxV!ZEpGFUx>GP`WJ00}-^>+jB zAFq;I=1*3ahK?T&`7>hU&MeTGY75)s$&PAqoWJ(!k;Bj0_kmz;sqpF7YhkJ!S$C0_ z@jhTq-M~ksZT-&*1nkQJX2lQ<9I)1yUAVg1uP1N1*E|EbYjcUaebK(-UJ)6)Yk*m- z55oP*OX4O^2R0wBU8{H0JGRf_mu*I-3HFSryXP0}?GJ)p+OpJE+?gjYJSYkE#du(D zrB9X4EcMtVPdYFFlj@J{0K=7a4LIPg`Sg@FTZyBY@DSa6%*Yv0ui<&fZN+Z6r1Ux~ zb_KW`$tswA&;Nb14K zkSt%uDdprY2fw!ofiDNV;fWm|0*QT@v}NFTD=+<2UY+-F`o%Ho@+8Vd$V#Euzw%-% zFPp7W+>)De9B$-?6ARpEVz**0M=qLWBvC34J{i{=ON1y%-1*q-O<);F&ErBjlVHVzQXr|-Jy-DQ9$S5kM#Kfj zv0+%SQe4=$H*W}tx6%7NAu4L$3LO#}(^Kn2E-Hq0U z`OT}wb#BJ}QU$^t^3fd1ls$R)TVorQ4M@b@Wo`T7?WO*eV&yYo<0aV@x#aKV3k_ME zZa)(9XaI&tr$^0qwucA9`^R>9DPcWkTeLUxVSq0hUI%Y7NkCbc)`v)E!?zcQ;65?G9TDY=rS+y0sR3x|&mAAsUIanIP>6(Pa?b7HYQ z@4)rEN)sgef!nJ|B0W!a?7@V>v`1NvJAE7pA=PIqVwNTKK3HQU292L?Y{y-2^j~aD z*j!@rCh1v=tL8Q*ES_L6FO{|fv%MLp-#0^32YIW(J!>Qh%rci8O*!L@<)B8E9{fau+ z6@&Ka`Pg_$Br40nW+C4{cdD$p&@~qTz;_F9op(|vla!b`&>tPlV&SVh>6pS#I@9n7-Skwg0scP2W5Jp$uer<4 z?upRD=6msl^Z?z{H9UlZ5EL{_Q5Q;qFm7c`d3(FOuaAYE^?JXi9i3F4Bb%we2Wg0+ z7gUGfhXA&vcM*}>k@7=xEdosyPv%EH;eBj@d#!mz9fLkMP(+bfaOSTvA-QqhsRNU{ z@7`be7Sp1{Qa~mQOz|+=IpL7$U)~$#LnNWStR_~y^GspGu3JA0Cw7If?qIrxIw%@D zD^zS(p~M%R$r_d<5K;%G%wl5GMrO%O2-&4xyB=o8NM}Oc_Lvt2nh{A!$W;9Dfm5~# zw>tD8**IY6qTpx@Oe>%jzid9{B?K55H2wAQ!9#3mZd*UD)5=`7ekjHF-K^}04+Ut5 zXLNDuUQE@p66>g_Ig>eWK}*`#SrIaxqRzU=6}79QXeMncDAGAFCHGeA=9Wc`vH5A# zqUYr}In5R&bW-hwIWHljoY^rbxP}=NwMYfF!ASnV3pJ*%Q$pYCUM7F9MqBN&uUs&_ z1r*k1u_v;otTg#w`?${c;EC^oRg1qCqg_F z>UGwym1L-hZQrpu2I)Mtin_E?bOfFBrn-5)Cd#t5M zJq2z-8WwA${kXJ`C?0H{SU5K)O7xN zlN($&d6+NYuidg7haae>6&;(4(QWe=B3SS(kLA~ccng@_>A=DZqs1$AO#UQX`Q20F z$G-kjh(NgI5e47$6*^Dd5u8#*#}vcblu?#uJoT`zg@6+8rl_yCMJH=B+H|ip3U(bp zV^00h>oekvlYbk{<2~=L@OflIF`TpqGZ1Q823@-I-gtoM{{$tc*aIP)Af^jOzaJPG zt^+t_20A)aW~rN?NZCUxrK^u-+TW4C&pNh5B)wn8aemb1!TxNCEc&&J=BwK_4`uui zoviPgjoYZKOm0>|9Y!BLy zkx1&O12=hX>U{r5AMGsly|LKs2TeAZM^MJGdJ9T#3rJ95_^?0YAD#=e!3ZIsDm`$g^8EpvA7yx| zy0s1)qdK4mcd4nZ#s?ExJTa!cY>n8o+oS5gCjj0hj(qH*E|-PN%_3H#(C7h>3qx_c z7a(r>$pAfi!BVy{sFF_h_xsDDyG|bS8gQq)0TP%7mIz`KJ0HN=IVNP^w&eQt;0=Wp z`Ad1-dGs7`;>GlQ-1%5ZHZnyW-V-ycww&}$W2LBQa{UM+F#X+HCvO{DoCraoHft`A znUJz^_MYJlSzUS(fcmdH^uLg@5~``>7nNfMA> zE=f9Qn^^H$73!XA(2>Bjk77Uo$yX6KJrG+~Xqn9i%g3f!Gd>3N0m+Y3 z5I1mvjP@EbWtPc=>?T4j#-zSK2ROcBLUd7lAlG6}K6Cm)a+U*}aro#WSb~y79X@BW zs79%*-Xai5mZo`#8{uGF`Ev_R&%@!DaH=h)x{9`YOiHjFi8?&RvWSsi15;MwdTQvJ zN&7JbM*gZ}on+*s(y)-^8{g=WlkXNa=k7c^FOhAMwO= zj?t04)*2F^_!ucu-}Oi0dCWS2+rw1j#K9r_LsF^h`O zF{mg*fiVi4+n}bzOZcCXNvAAM0H5`<&0pt-+r+vm8f#FHEFttY#9@1+*WAN&k0&3D zwvWb2vM!Lqah#_QEPuJrGJKF2(0P&5^x2bq>C5MjQSBOk(blMnI{Y+|eWbb2jG7?n)bv0)CbPK0$_#HByg`@e1 z`PkpY!}s%;j=ZENO_3|9e9%Vl<)Or1U$VjjIZxlNCp~4w+dMzi9x9+L&&Qv$268m$ z0P68L3<_suo%kN@ZIVY>KJ5crvUWQKcJ;ZO!n4w9i!SPIAA_Fou>yXf)^TpM1aafN z!_##NStn;74LT-uf{_DE8JyPdt4pZfq|b_SL2bT%9#^Y3T>e_IqS8&}gSbK0SovKG zFCh9OB`o$}>>u$WQ9$u@X&A;8CcoVQcx;s$nN)C0J- zti`Q&Z|o*G#90wPxr9pvB8GVJ~}ANGNgH7mxWv4@><--=E|^E0ISDCJ{VWtJ9C!#tOTa= zJ8E}_iWeeoK0BJxqv;}Zt8I;!4dk^?H?PwkyzjFhxA;R>&I4o{cg3NJ=^YUlv<4g) zS*!u}CV_%nkdLGs0BFxa0+ z%4*70xJDj4E)z$J_ZS97Ap^oj)iJ2y2YJRvpiVlrBS0mto_zuT(@MD8YrGB?-P;~F z-&na}Ac|B&S*A5PX{V%WjR>*wS_myjBHQwhYlEN$J^&8vg0p>pEo&vI1Lsn3gg*F+ zRbJFdHDh#u>0hmhB$GPFxpBb1^I2^7rG%SpG0xsx!2P~5E3SimW!3XuygR+mKx7o! zCN%QK8Wej|dg?5qDQ;qiR;o)9FQ+VneI7QlwD)RdM4RHh6Wah^7T4m1u?=BQ-{q2v zW+wqV9_gVDpYl*xTa;C+bBnpp1`3l>XnH8p3JcZ`0fuygi%BeCK+_R=I?W7Zir2^e z+W2naPaYtHiyH4H_>{2>Nds5CLE9+O0H7xYnEdZ$rG>6#pGg+L=Pg{%X5*>1_(~d4 zlaI)c)fR^&nxZTR+So>~BFr)BC5I=bs}_D5O&-pFBG8Q+&H8Mzun{j#rMR>oahLxb zP-y1|?qQ)czA>pYIH}bmJG2kt3PpvoPZy|IT#%5h5u>6laXWd;55Z0^;edg z^6<-_T&&E)dyS;5BXqxS&&JGTW4d?6?S#JDF+d$I1KE$KJN$W+i@bP)RTAOf=nJ6 z7pS)4NK8MtO$34i`GCt-oU^D)1v|ve#>&E$-39rGo41A`t#uYGOg#=hyS!NJBeF72 zdkipYcpgNH0Ca`80wV)!dmI>-$E4V4g45RJa^Sn}WHBfg&U)k{ZY%?0)=m>4Kj~a6 zjd5SoDqpIyn}GCq*o&8Q-jjXx{9D^h{xcVyK*j7(Zj?3t8n~C&TX2!~^VcWZOmkt^ zjNlXCS~;L$>Gh^b{D3v6n~HFdfVbvK{}k2}0Mc99N#Not|23Y$>!Sh6u+b9iS-_u3 z662Hs;)O=pb%c#7`)%GTEIiQ4L&vd}SUQpf0FT>^H76Aw{nX>8__v4k^S; z@voQ?{7=4#6S1~%S1A5$1}afp_CavMAp$6~p!2?SN9f%vdNwm5`UE7VJXar1JVNf> zLPqRqLeZ+0nlEl8-Jkn*hY8^ZB8qB^O;C{^K7Rd56=s3lL$Hc<4uuc{(i|T;>W!bL ztE%F&JxM$n>&MA&Lk()7$NK&N$Ka^- z`Wp36B;0I(ANNF`A!b{JqXX2NoX`BdbP6^G)d{xE5Xce&4!Y>kH&)5Pt!aZYBQ zKx~Hx{+L>N*IKWA8s9?#MYr2~Ka+A-{yaksT4HzTg_j3y2Z4mwUMq!hU)9OQcl&HJ z);+qgoH<{GMtllGa{1il#kxRt6O|Hjgzxn?0Z0L+?B)DCNWUGTj z`zJLS_?$72{-E@ zF19YAWGM`Jt8F}#lYr6y_0WdabECB_3V>}I;m@_kbV1yH8V^Wr6^pYca#gt>6^}kE zuR$p}f0wyI2^WDaVR4W=HT|z6)?8Xe2lM^ zWV?#XGeJSOOf>g(Xy{*ZY4uM*fjXh!{+WoNdyMLmFazNxebj~5_h6IIL^1uv+uNWO z<4{d;GDl}t!#NqsyGV(ZVJ5##!D#GgRh~w+-@}5rxx|c*aCV9ZgZkf4y zoRR$F$=#&`5EHJFJcMQ5nOzU1fa(IxvVTg`kBGKOcxRv3*vT;>Lw(1Q-lu=)(7a=V z9)BuE^*tq4Ka}&N)!nLGN%)x^?iH)1AgjfV2$kHVm2%(#M648A7abX_GB>|&H<2OA z$X<0!Z0M3C7!b^e{6l_c85zJPO?a@I?ZR8;pnUfF9qk^C)jXltE3@<sdSTCl6!mAnK2@8>KM$@yfBTh*b;yJP{6U0E$J2*)8?UxO@rEc~&de9M zsZ&w_U^E6M%_uoKpbdXeS?G|O zzVcFt9Hr1@!}tM6LI7-3*}}Ro)K8wfytos2!Y7<`FQ%YUD(cTG^j%&RW8GFaMg;w2 zeS#w44LvrDgN!?4W`l|{^zZMUy)>ZAhcUJQ9Ah4Ar>bn&bwVXZy8+sC$=&3A`ngN) zM^&hfo$=wZJQwKR6q&u`JI6qASkLHnP@q*%_qoECKJ(Yg<9%1Wd#mo27*ro}e z^#eJbg5Mp!Ti>P*aGz<9v%K;om;_2>E>}`934qkX- zt=GpHa&bl;pFI?GCp98=iuD(6-wvfo@K?Ym+bWE+SlvGfNW(D!VH@LdNrKV}VEe*_ zPd`xDP zQ5g3kXwKT0_*B5tCV@0INNZX2nl3Krd~AC9 z?UD|o8kA=LDBJZ2SY89GOVL39=rnH(`JwNl8nM;!)*rsA>vsg`?%VN{Vqkip z8rwJcigt@s4rpwa=$U;W<4p~uW)b>)X3{{#mfgn`k<4kZnvn(AX6sjjLT-cz*fi8 zBM#qxFdW@f-})4^B;ZAA{WnL!ruR^!@eI%)$H19wx0R0dJws!Fb zC#WH@{5@L3@AI-Z@e_YdCWrz0N1-N|CIdL|TKNSyX6XP=Xtv9ppN4?)>U zWh6UkqNwQh&x;uicMkzA`7G`*ajhzgrJ#_AQ=6%j?KEbh-ydI$pzNOzu_+?T2D-A>N!;sX5l zAo4d1d(+TBQH^=3`X#xisPsiyS3BrIn=8jlogUX$)i5DD`cAhy%*5w@@vjWf^jgkd zo6MkH2bi5P-4g5SU!GC92#W3vgX zj?2izB<0nqUka-U_k!Mhg3-h>1U$mqoJ5j2M&vdx0`t0J>b7)%p?;gl$&`$c{Cmj$G`kC8PomL?xxBU^IBN8*s-Sq|^SLRX` zL*t_z3K~B1(tw`9BLRAX9a{2`x|YWN<%9Knf?{04SGH>#1*+=qdmiCPIYQr;C2{xD zb&SVx!Ol}1_G@9&2E1E>wTjkC;|eQ+MeBSNydNmt!(lsLJWPqYn!8SJ?!Rs>?Lli7Fv{M2bU1T0Y}b9+CA0hBL|*Gp$jCIp z2u&QjoBcz6c1p+fB9sxEuJ!45WlgkpZM~;4tJps$z_W2Ic{uw4)PeIL)!69($4Rr0 zNslZmI5k-;{b`W|R8KB&EdOcx8=*EmrZ@EX^$xN z-|ZCV#>hETGklcc<%e&5DJRJAVVL__o~n5&mOfrF=+8<*Zv~4SiZs!@RA@Y;U$$lO zHHNk<^kxR*bPSTuKZOjn>(@f8rB^B40+#jQF6T+mP{3;1=oV*`6(r*0q%sCGe}4jfj(DL&ZF|*zFnuAJ^GBd z)oC!Brp;MoIJpFAiKX+MK5MbP<70FMdE)b*z*$sX&Uj-g%TraosKqdLPV8@>mw&Kt z!i2R+`5AwFOyA$RYkMbpowm+2o({APqj-4OiSL{}N#tJ##lMh}^JXo^< zEfRL(Y>7!lW!v(8h_|P)LEW|K?P<3jSohzIWU_TwdBtyOtne|=U-Yy0Y1$=L%t3$Q z&-G+{3j1^j(3)Y!kYzjyO5PE@dAq^aCSt&NT817f{ov`^_S+9f{rG_A&@5_X`aPNx za2|I9QStM56Ni}39$;x^S9(tSrvtloPWf@-i%l3^dd#Y{`CN2QxiZSJdn-eCYOTVlreX^z4R*WE!{imPp@^lqHiwn3GIs7y`sfR zE^=sFtkXcREA2d8)5P=ih`zkGu62n_yf=|Qh;33=8v~W{VIBY(m!^cnf6&#%kNr+OX{^A=e$p^Rru!fRvTg~6(s4`=N#@$=}^W?$lTvA~FR z%}XM*^Kg{fLr2g>;Y#O^V0;V7)@T;lI#4UrcxR6P&Fp!4`rHG-&&Q5QhOK|P>E!pv z>Hz6h%31jxM7X4l|EZ&hP3*xH_(a1!;uc@a&zKW(pwIF4dD4K8GqFC#fS|nCq~5Fo zvwT@{>`I7Qz_Pui6~F!sorr}f?Filh9K(r0tk*Qnmj@?WNH|DPi1@R8ka&j# zGS80N0JTSEe(j^TloGp|Y5P~dtIr;gzW>4KnnEtdEkySIapp|nLsrLfOYce4_V&&J=_T|pSH@oP z442O4-Bwk#pdHl;TGj*C?60Cn|ESnPoXPK#8n)QcJGdsZxLQoVo9V*MQ?;OT`0lY* zMbr!SCCUCrKiF0Vkdb3J@PtX4c&`*vQXpo9FPTYc1woo8*cx=WixDCtvyz%qnil6h z>1Lf3%@I0$GW4;lf&5~@6NRewOay%dNp%sn!5)B49zj)0GzxBNPuYtf`7jvQVaC`+ z*V%X=l=gAYEqU_W$B1_|AV~IrLriS$-U+$9NH413BrQX;p}*1_zq$lL;tpzlk2^rn zi1>5sORpn_=beQLbhVPl^@%yv?kUaf^e>0;Jo?93QNQ^uqStu?F&JHqxnE$4Abtr| zTcveZsv|!3;*q>sN2PHnUH-aSCi0%#uut-yEj1^-vL`vcs~qXmTlJO^i6R8UhYH%1 zL9+_l4*d&)swHfr`xrB=wzO-^OzDpdg`zz$vGkmCnY7&K*g>DG2T~8R2@7(LtIKkK zi1ZWn#55!qB1P>%s}aV&mVIlS$-n!NK-bAB+@_ha#|KhBlfYaWBC z%U^mgE&bVyW}D)lp=Cg(I0?3uY(00aDFN&2C{6ZV$}6S8JP}DBE@voyJ(RH~JRxBJJP`DQ7lpDXAMB|V1tzO^Vow_a^iihE4h6tg@T{Kn zAZdsAJAHGod{B}Alevw}N{FkLU|b8J-S-I6xu>KIWp604*@i`PRJGx508H2{R^01x-)W`vhN5nZ2_p;tEka3?vX^Wr< zyb$>9%Wz5f;ZsGR4H~yFL<9Ab*LHwnwYQdDLvgIO)uQTqv>kW(A&jt1%n-<1HNm_v zYxmfMryar?3cx#t^V%t&K~3Z}xPqzSL9e2v(h~uj^~dY9&k>wWmAH8Q+T3w1>M%ey zDN=(VLpTj!wm;(8+N8OG9%U@B>+p*tR0_Cu<_y}7XB3AY1TPcvfXgx|f{8;xzA(M= zqz7kP*61tMm`k8P-wKuPotGxG`N0M=q$Yb*UNv_CbY~C6azdA3S*#~N^~ta}(2MLM z#~RIs++y3$0&O5h%J(mH*#llexyzn4Sm7vP%Xi6&g>|0m%A+0vkDy9FNiw8COTQ%f zM9|(X)i!e{5XDmDiQEKFQ0=-`cL{lWB2#|>ajUH=f#jB^IEEsLG}E z2tDN^$m>Z{uim3+{^oxuXvgV}Whbz)-VUL)iLeOqKOcP%$J_yY!t)A!RtkR!mkv7d z2-YPua>%AgYM`7_Q+wV0?7E;27UVB;#pJ?Tz8R?GzP@V!-e`sMgG7~PG!A@8xV~p1 zWklX4)kC4`41(K>s|{og2L1H~Kg)t5YEH`&bH$->_=-eI)aoMyH7rfYjcTKmlZxrq z-h*V{inSA_uw+1e&;!k_MLtWh-bBuo0ge3I-6cQNSb4+qNI6rGJTnH(rtQ z8+mjDgNK0kdL|b1Z+VBH$^fmH6MSB~6AMQlt5T)F9<2zjlEYU{z~uvTY9cvT&%i;O=66s%+ki<+*^wLWt?P}IrR<&=D2{?^99fg zufb?cStHlq?o^Z28#Ovt98&23o>2YNWmA!Z+nX92Ty9y0GB_A!69F`x-NxBh=a(-jYI?`U(t3u$9Wzuy}d-&gsZ3=vrR?WcxTavTKT^&Uv za}jh1kzwMxqsFxBG<{N6RE2dnczvnky_UgeY`cOh?HEVfVW*%*+#xSBWfVaW@jB!R zzw-^DA8a#T_41^*cDZIA6Ks5KWKHSHw4_ohfg;H1K9*eZ z+X(wQ=B%~n1@Dk~aC%Jkos?VP|JgGfqUe3#c{9FF>Sh2O(#hS%z9q+)rJZG;`*6gz zAs1N}DC8vBDC9g+5qGtzlAZPVSl4`S|NhLMKg}6F)7&qO)9M<>L>bC-O=EuNVN|*@ zZ`l*YU^Jf}XpEDC(bR69?jSH{p465lNY&z^wnwwudE@pyYu zXNJ8-g{9d9uMzY|9CPig-CgaNKb$bi0QvQ?((&Yz8XKGEEfo=>o1L49{SF%rwWh{P zT^m>S!UeH0rnQO{^OYA)#FmqjamhzE_iX!2kfK$tAM4<`a^UMDZ d55D|@nM6LU0Xczw*1yz+KH^|`-`wZie*@#tQHcNm literal 0 HcmV?d00001 diff --git a/docs/Images/readme/CueCrux-Arc-Loop.png b/docs/Images/readme/CueCrux-Arc-Loop.png new file mode 100644 index 0000000000000000000000000000000000000000..4bcf85884b57b0f0440ea8cf44cb22f42f353f2a GIT binary patch literal 20152 zcmeIac|6qb*El?kEi$%{eP6RPwy|U>M%F=5)?vuLk0mlbB~%E5?8!QkH6hBBDMhI4 zWtmizb)-&jk z41qvck>;i-2!s|-{l~-rMji~;>Vf|q3N?3*fIwKdsQ+jng~dm~7|GAUDbmTxQr9aa zNXgSX1dUOO2?_Jb<9^VSzX1GiGK3N^u;_cM;TTc4lBS}Us)n|xmX4CDriO~Trh=%NimHyXing+gWI*YRYPAiU2|}A~rbE zGe$8uLgHT-OfeB&;eMf!ej&l4RE(bJkf=y~alq*x5rRVhK^q+Lx0-;$lw&+Yl~t8g zs3QFa^!EA(E;K4U@HcU9FJ(+1CI}N883ABb|A7rX9}*c7aX#cfLH*C?{~H0IS}Uu6 zX#9t~1O@#=A|mnx7Krh;LjFVO2#45Ej4}!n5fT;dg*kx*Y)bq~nutgg=HK-B-J>RnPu`vI_C`^NIZ*ptK#-RCP7}0RblF?HTF$p8|P%>H36(2YCX; z_yu|TVw6LJeZ@upQMay1NMJ}fAOsju|M%la6BFC;5Fful@F4ZogYDx$r>ubw`h zs@^Ja6-_m7uYb)q4e^SinhJIPAFuHa@d7yhjXe!bAGi}?^h4ECxsH>|h!qFOVMQx0R z3gA!OQv-a`Mr)~4-Qy1?bH50%oUwm9oINJ&@1FwwM1LEZuBR8(dGy7-s0)wr7XN$L z??2GTe~a?p^P|sW0Mh^1ApQ`J2=R%G_6)}u`2w~5m$s(-pYk0NjKzfiJI+Hr!#zQ` z!h}cYi~EF!1d0A*ETWMiqMo6lfqq_|RGF2r!QOv|gnw2^{6D1=;fei!*ACj-Q^iXM zjaJlB(^OT|(gEwMUbQ5y|cQB*~1U{t)+)paz{YX9Q$e~{zf z9QuE=5MKY~qW>4`Of`jn?BYLHmNzEc@82!^zc;OaSP=bfWdCdE{g+1e-wR3qp^^RX zSR7^Qp8F@LDF2V~=Fjh@e>8ZK>WII$CEfohvix^#4(wC9Ag=xwkyc03)5lB2Q&SPG z1=m*8_R_#8daCJYDQb9WYN%^?qtQNEaH<7Uv4#B4Mp|mX_^pP2mx}yr2;?`^AOA_L zz%T!#W|&~$r{N&+Qrrb5m zNnF=D(AqJ!GWfSlfcdo z%JAH|*9RvFT-cxkBkW~2U_z*yCiwfjob+L;O*q+1mNes?cSJE~8naH3m?JwJln|n( z2QS6mgV8QfilE73fppbMIXYN$3g0VbYUgtDx}fl3L9M+AU#X8pX^y>f&sqy)i;I#P zxehL9u|MVVxKQ;)^81i_Y5dn0D~BJ>=>7N)R++wQ?Z|*Wv8$%c~Y&NL!v0p5^3WJkZMQ> zc)3A}E$d_N=`GweIkF>hGGR`Wj3r+nnviryOTL@sj7kDAr+m1cezGN75&1|A{O}QD z@}AwnBbG_JX-FWQaPMDo-!qa?s4JZ-We*H;k0v`H20wkNxOpcjk#3w5!==}6zNEoY zRjK<@>g4?l+B|4YWwqVdkRf@l5&FouzHb_JfghQ>IeDuvHt3oU|aWw`-U4j=ozY1}B?$0X0%< zuYms^-hU3o0VRbQ^wEfj>__|6EzoMg4mPo9uVH=jhwyP3&c*JFtP%~~aD?wcN zOU2h2wrRS0sBm96fiLuOi(7`RMPbG#Vk~iE%4pQDVqM;y#pUoG`@}hm^zScMAldvO zIuso;l6=ld+Oe@BZ7!M(Isr)`Gbj_nioZ4#*w6Z>ogi@-iuCO^kLl&JYki+C6EYqA z1lF?nYn}#LI8?G3iFOO;@e|L7B~CNObMC04>FiOQHQiE*kRgUgu<3LRYE|{P;O%`^ z@+qRK_HCuA(95W$8s`}L zvZyX6*($8Fk!3(4G&=BySE~HMzND$)AaCJSgdFmJH zXAE>RwZPtGmuTs7OorfgDs=!7EVS=C+=PGTQI0S4gJ>VxiJtG)Lw3%dEMER8H_xJv ztN?TtbgpX0{MdSN@pk3g5-UOVNHmt6fCOYB1dT025_7a;oKfn7Qr1p8f=wz~S4R)? zSjf%kk=4itkG}*FtcGa!OSPX3wB;_rS*q~M8sspt_}*p7w%394M;p&2{dnPAsR3s6 ziIHNnwR{+}9Ioc1w&gbVbv+(40W7<D!d7YA85SeC`L|^r41Q5Td^86yN0U zl0~FeT9hD<41Ah0s(b*LT^eLGFcPHy_=|`#6f~M zv2h4}_uF49qNrRT1l$LDhC?94<&@O-cSvGpD&ldKb=+wzgmCFJNAyA5<V!JW*NI9clx3^eEWw+@8D8c_TsEOCbmSp%|3J2bXTDn zaGB6WU&btrYO&ipGxYUh!PP&1Q2I(pu$24}$4 zFQwLg8VEXBtn3LVeEt!g)DAu1npA&y;EZYoN+~!8i5J#ZLZpsH1f;ztS&_`=VYgL+ zrLWF#Sw57s?wf@gtcmr1NebrQ*Up#4pTbF`eaE{qxG}~T$=*X9)A{78Uek^6qNmtm znFzk)T*(_o9$HPgvgtuWGXkO(pA@zZ*6onMfOTal_+k?+-u&a_n~$1YzH$v> z8Q-T$1k6wjELGnee4%A8U}9}Vv$U+|X04aZ`+dvtTf0X?J%QZiS5gJs8ziv4UBak0 z%1*LUH(6cSit$3G{MNF)-HbRbmh+I4E;B%Yh$^qhS<94?irs+++4oT?)6}ni-0|v_R;1-D4MW zutLsK*&wkiX%QOjQGj>gFq0jNibx&Qx&~x|zh#O)8iPApg0HjyEMTrB^)NC33x+$J z3GTLP0*AT?__zb3y;v+{T=&9?$V%)b&VE$Lj(cuQP&y0Q6GdEhxP(Y0tSY|Hk^Ej< z6g~=%NMqHG2=_A2JqzvT*XA3jtYiRT+EtBhM|y4Hbo5<%gF}1tv*#rUMnFGTPY~zk zpI1KcW2M-U-%S}w`YG^OL_MY@i?o=Sb33uPAdgre{S{cM-mZy~yQah{vx6YBHiFQP zqxUPHwc6GV@<7~0_GP1<9wO?;>}6K+gypxt^{1gYdLThyl3ZsjWt~pLpil$a#stkm zXgo`!y@S@Y4gQ4{l~%O^-oMD16eOC5Y@4Y`lfd1VT)a{F1dQewkxv&dobC!@m^F&` zlth-0`7PRB_>*_Qs?n^|x?Kf0`vA`S+AP{Kh|3x#%c%jJ?I2=R%2O$6bMLrdnfw?u zxhk^FybAE6o*A}vUry6#`KH|PAzvc45lcZdZ~#HDFz`^=c;%>cH0?U{KJavE;2Lva zNfPl%xl!%Ov@;jhn_ej#&RSJ?p53WP$hh!IK++-=qdmZw7EEfD9)m3>vC*(mXk#Y$a;xK6lbvMW*0s&CRA%5-Z2I|a>_sx8CC{h z;z%p7B^G)pQGR_q{Kj+~+DNxXRFgy6d|;|-8D!XBUtxbkHzb7(TOXvtV#*!vFDF$2 zw5oxOvxftpQwJCE?P?`Z;0MP1y+Onf5ELur!Y-qnVbBJ^l8}c8g@?Qk1Rs^ou$AwP zCl7$>&}rzNnLJc^hYaE9<8uvk2+e%-th;kY1;_apE=NS zNDNs5VtrlYVbvK$Ob0AR2TZFg2Ga^yr@^8;jFO@Vd)Q#vkxNj(aBikAqix7Tp^jsK zjqhmy%!#JB1c0?>IVpGQ=%h$elS53A)%0=kF+ZVDh1sWyNI4f1LQ4XKP36qPHBs2H zx!hut?6?7Af|??O(jctdE!HqpE%;GZr32v2a>5(%)(xW?M7DRiL+okxMQe+w7s6(xuC2dBiV{B#Y&u=1f@ zl~7t05Wcd%MK+W>*ntCu?czh;4o$$nUp!E)Y&7nSvDE>O`pg^Ao%;U~O7Al@RfG5lX z3u$|M0e23VS9YCO`KUKT5=)CoZJPm|OFmcv2gM0nf3*}KZ$KxFS$5nL4hyRVwpM6u z?raJMl^xe>Oh|i4dm12Jj=#}?vdbRj;<2#uJ^`=}wGo%7T8sl)%u;WG);cyoXQ|8T zV8~MSOr1%vOvw0d7=4)D4M{?Z0-k@E)&s=cv+o(my;EY6$XM!-*c8nuvpXpZiCoeL zlUlVAIR21hVO8^wJ_=@6dh=MM`y#Or_*)p6n`jHX3I%nNg_oKD{+h8+WqK?K9g^@% z$*2#`r9#Kk?+G|v225*QO-6a~L415uY(K0pxMhH$NC?2Lc1=44#lITraf+(1O@N6f z(f#xBKH4IxatdF}-)h#@CA^+xou+DL)CEv~Dm2R@VuER8hkJ-Wt^%BY!d)69Dv<&*u_PYbFXGs%26j>Yk|s+4d7gqwp^mZ7`SOGluyB@9|0Oq{} z@`Gn;c%kFD4`3a7z()uOunYqYE0DUE)?_xS9v(aebF_`8TpNi8kFqPXsT@uLCepZY zcc~K003&h|9){g|<7zGFp@c+zp0ty_BO97er&$t&Veq98@zQTP*OFU=e4qzWg*`r)wDq1wlCPhS^&lwFy@^r4 zuZA8S>ET{%;+$K5ZPb}Tw*@wONk2WFeynx?Lyr$k#p%uNHqEj{Twe8}^xlCRYS%Hr zu?ZMZQ3y|H|KY@-0)YsFGxMz)a0G4>m?z5U5^1ryMQPd=3Sb(apM9>zQY8?vv~8_N zbV2P7(grhFTMm^ogOBT#v^`j7KRJ&xX~Si(8mmt^o_1=*>d~(Ya4_8ruPu)un3rc^_1Ho&IH%~2P zw3_|e93++_bsWT4Fs(vvlnD{D&TF?4odBozyC~B($Qf0Uo6*GWhx!t!b(r$N`xE(; z>(B#H-e%rO+xg9Jkt3aruAoj+ZxS6T3FGdiqB&qW-I@tNxet1RjG@wwlAJR2fJhXu3gp!%)n`qy#q zj2*tFM<0E+UPyI#xuK%1wl8Nz$Zq>+jlDFU(i=DyxAs`dFhrU1BD-u#Cb1aEEw9F? z9Ry60#{M0t;!2CH=CF64!pl)PZoLsijqk!BNJ-hV9kMEXc9xZhcKzc3VnB3k6^n@8 z`GNV#7i#ljc;!Jl@fR?0g0Z?QTP%B1-AmEB%;Xm5egmcR_hRvh!k^s8BT|N~%d=Tj zf*L7kb@V~<*NMG53_#I3<@1XN6U?PQRIKN$$KuGZsr1T|j})<WU~DbR8EuSM)@!W0dNbQnwLE}fcWpgz@quo~<{Z7xlFB?&c}o!8xFcoye%H~-Eb4mRXLmwPgX@0)>eT=$r>P5{}B`x+8!PY)0^bu4TT-hP1S z4XORy8MJ96Sb`sAb8L*#tDj%ILkD#Ge5V&R<_;0qSSU^)!l}#1(28q6vzL)c<}gn8 zEq|$HE|_WC{)yXQ_ZqiB7wbjFNopeE-*kD&ck1*w1;*`N{_;#8tB#kmdDMw58jqk8 z!@&>kcD!>%B|7NqI&WXlFyZNs4>=XTjpWvkX6mT8?W;A@)e6*a#gJrJ|HV~AA_Q{M z-UDEHI`h`vacslr)$q(L*q5D=OP6|+lKAKHoAoU10h#>R^UJjTJyRYe>`$$;+iqx+ z49V|CGwOjonPyDzykxZr(J`Spb;tF)l&OTXW}WmM>L6H;c?*ZS4X(Q+7e(+77#9S< zewc|B+k0LaB!1%7@A8|yRFRYY^Mlh;$(rznz@hcgBTljr`pO7mll(-O+qw6xMQE-j z>EC#6XbY(IHY3-^Bo*+Tb!U6DU27b7R)UC2%w=%$--!q1+Z9o_UJt(5XV1Ed_W zI8WcxdwWWmsI_Mx&-fMY@^x2TtJPnSr{Bd&ht~6k|G?@3b6LqMrwc-kV7OrSOO)hY z*Zsvx9f+&Ww09btYS&QxmVR8uVQ0ls3j^W{|HHpza|?z<*VxZoa+2MAdE0r>Pm#vW z_WkC%_)zsq_OT>tHbgiXCBm(dCxQDhCHBpMr(e%%Z)xcXbJ;_-oe*vVLz4+D0kFeu z;=Ec+4hQsCpJr{fUGSTKU+-%l)Ub?uCm(;Yq=60#cGOD#l2RcLd`>I$GeH3#3mb;1 zWM~0q9!4&1728k)UZHC)02q1hK0vUeLc9PF!|c)VXFd(%Sh)>)V9^i+bxTUmcn(v! z!t2BM>LQgNeX{^|?fNH+>oh}mDL!aJ!*__l$#M<3>DFN6maRK1hr5orW~txtLGR($vVT@1&FIssmWJ&M z#aXJPTe6pG7Ka(422ruRd#Y#2vYGO-Ez1_Exh3FftZQUiECY zdLDQ0T-`m^onKey>@H6zSS%H3&g9N~^ZVfj*`O@7NitDY6H zF&hm0OJQ|JF@fDqK9^+d+;cyX{(Eel;nsO&)tO=);|}SKnQVvlDI#Nw$&q`qh~s6> zvda?-a_by-sCd4PtIV1TdPyP^Hl#t_EcLIqku0u@P5@*}E(CXnuz0_$5wbl>DTTV` zQ>>BwYLMbAq1$w>J9}@>^7Q{~+c@0cJi3uTEKIiXj~PDS^@kz4nT|)4?H1@aklkK% z)fqgX^@wF%?-bebU|r`6(<#-LBe*LKz-+VW?`=Ch8V9;uubHB;h(uYfcd|~pjC8Hl zf6>n#rAryPd(OuP-02+y2XyVCxV88hSa<7{?ZDfQ=H-!73^>CkmTJ8!DE4c)T~D_Ia-Y!2U>vHU535pa^SZTXPY3m7#Z3z1~ej%#-)Q`w^$ zcUqwictOCXM)cx0@9PFO9 zpXD&j2U|AM|A8a%Ho$T2hS04{U^wrJgl-vc)~^3-5F@9PzF$9~GowgQHpmsa1#$?m z)%^?_hS@gXA*{Q!_Tk!5^$rcv8IswR4d;xu&17;vf}>(w?Xl=sn~(OyW&gMdC{dZK zYtfyy`-t{Y?Z2GNHp8XeZvC3O1CvFvhS^|og^{bYS*M%8dL>WM_=kR@w70<@MX*t{ zz;&kjahCzONQ@F?nAqbWVwL?y$VTDR(j{)9Z>!0-bfEu(Vxe2o?VR>=h}KKjTi7Py zdsZOWC{e0b*x|ZYjvf!yu}=r3pE?CP>tT?*&V#@JU!JEI2ODzzoJ}iq^s~H&GdOT8 zHR}*DQ(~Ojy3Xn>m|ypO7;C4TV;buuF*;g^<9{U(>sQzlyuch=z;FpoaUR&Z^~ZOp-Xt{DvPw*Agn;rF3KT}&jF)9Gai)`)RMig$edqkIe_D8HIa;S z15OOgtFiH*%-upzQwdo&`+bTgyYotmPlBRW!GrkxZSRIY#Azvl{~gNZ^fF+r0)VRr z7xTAG^EitlC6Qw{>Gxu>sSGzi_q#e0fs4wtKqb2lYiof0HEJ|jdxj;$c6`W~aQMvo z(RRt)AYn?@3Onn@6JU^3DZpWxwTT(rQvm3fi!D$M^SOx|0N&Yf{V3~!P;|m6P*$v% z>!TBT?srfKq+9g7;|bY0s&W%lv2@A1Q#Aa~y1D~=0IDH?DqLgjXI|y)y$j#Il;#NC z3ZWViFc(jQlmJ&y2VR<kx97`txCV^YOxmPNA3tpmqOpP|G`CTju*)zKn8!s+CSV zcgNyfwg&tdwFsp#`gn@wCrAN$pFXjPW)7Qcm-Gv7rIv~`Cc*Ln8&K<;!vGu+xKGsG zn*JgisBzwYtY=i|10u8gFzl6w7HtZ3|7AGG;F2SB`~AY-)OucmZ>Ml9lsl)8{KKF| zau(DWsq3;ZSt@kv{SXo4k{WpEZw|H|tA{Ap)IL-C*?!e#AmF4;d< zW>+AJAD#^X@Q9UXjiuEee8?2Ad*DAxdVrdqpE%g%4**M;M@cC=7E5K9aG-E<@70Gt zq!*6?Vm`1i{3~#E0e1Capix55-`^16+vg+XJ?dVRvxx(B>a+f5{s;+5)wik)XzO1B zx8O!Fb?72Yuf@VJgCG&u8#IV;?==~gih2hs9%q9=ga?+qxl{D;<|Ymlr6mcpH8f_v zDd(HT=EDzJu0-JBu9*`q=%8*xu>V?S{BwMAT38+Ie#Utw2lKhgoa zSppPf5gvfW!JP7chnr4eunsgeG$D__up(EZIjy7e-|GPOpM$h70*lM&D3Q&}9zD%M zfo!$}0#GxM@gZ8Eki+c~J4~;(#%{R=t)+sEDQBTyS0@>I3l4 z;8>CXa*g(5h~tcRX&c0NI!~eO6PTR9c6AAah|dyin!}61_xy{E1%(d`Tx=u=u^9|t z6MAju7F0~+=#LL*g+@*m5MKaBzd$Y#wOULfZ=Mm50g1(?Lcjma^)4AH_y90H-M|E} zDlN7P@2Y29 ze;R{sjn3T^Td8PT;Z#;Flw7{`!7-9xIU=&ft$OAsnG`d=XliU>m z5$DZE5kfB^vzJ1}!|(-lix4YLaH?8)79|q3%b($3Q8$a8w{RNkUA~^_4IbI)OYV%9wcgj)pDQg9y-%i&dY$h)?_|k<8QZD_i=s#!`goW@S z+^WA;*FumZQTi&%VBTHm77!n}U#s2~-gjD$naRUR)Ej00bZ`d(Hk8Riu->5Tk@t`Y zof4xXqUO!ZtAIVgXWym1Mt+(C`y)uK1~;9skY7(|$srq`*^nR3(Zz#G*7S{>K~Nc( z1BKO^AGBe-jgsk_j5{eS?6i7nvL(qavG*a-n3PxcFU2iBS$K%*T&wgs3RxS1iHTNs zQB4s6w4NY?z&-m0Co6cUfUCjCGf?1S?Cgl{T%aY(QnM+SGMWY&A8?C>UvMB7udx55 zkB-s8CASoee-ODLjbPa^-00RJWS*u4_h7H=J9@il0JHa4QYb}h;$##$rKa+t6LUNq zak&(&-lUHJjXPFbmsTK!qf;bDcegRws5u34;{3Dj>J7CUSDHY5=n}Ddg}rbz5VYq| zKx~o!ZZ#ix7CylHJBcp}kP*&%$72R*=iJ71L0y(g15yna{Y!iLVYfhWQ8W5Ndmkq{ zXiUyYzDlX{aCD^Bm^28mO!Pqg`b>v`GVV3TCAElQ!mjr%t;oQ64M~`{h7KsQzmp= z{r>f%@3mEd3gwE}_EZp;rQ5i6`c~L~&(5Tc_DOkleGvKxQq1-eIVA3fj=-&Zr@X?) z^KBmmRrwa7>D8HwXJ~lmA6O7xJWAu`zV{S33iarR-SNRfa_5cFuAj1jI!YI?=z^`9M;5qDO&%0pB z>bYXt{JIEv3OM-{HXr-@+Z0p0HsZ2;ltEb2*Vmw{19tY%G`JvCzt1+AEoAJ~YI}d! z1XR2`V@di?eBT>=204LDUS93PhUc(b8_u%t7DFhO{f~A8DSUcNuJTK!)GK5MsuS^- zfeQ2%B;Py5HYh^|X6#OLSkgD^?Pm=#3xHr|wC4vVZ5@!L<&$E2S6JLYPM2QEYG#V$ zqt#Ycgc2Aso^lJoErTnd(|uggNy>c!*vc1zHVS-pTH5Lpp+Kr#NT@rOY0RIG0{U5Z zRzP=>y^xJdNZr~bsKs#s#@`8(c|1VNivPAMx^D?IhoE}9SqHo)>W5&rz?Is&b!&3e zlo%dOPiZIVHammP7-?{;9FAqmT`L7HQJmZ&F#chcCIMdLB!g8CwGBQZH-?NkAA9DP zBNk!>7-ZeWWpZ})jM>Q08j4jv;r(So~Yw_YV zM@^_4#cMvNp(1xFn}*DiB_Mjyuq>z8 zWbCcRo|U3!`AYQ+Q2@sZTFQ?0LFef9nY31GXM*X$6?S=lC$pFUH)Mtd&Ur6bM!< zmM8{P{u)NVZ-BV$-(pa&<_bchaVe z@C#P~MNkqpOfR7)S*^_*8MbsifMwMKi*J8UhagrPzT8SD_ zZ@IskLiE$-ZkRs}IiOW|0lV$M3$9I70aNd2i!I|ZvQ~YZ3EV4eF+4 z(ay2H8VoKM@6#^M59toRv>*o%`%(uHZ$OH;bKCSMh|=;y#&W608ipXjK(KM$Ym?oZ z+F{wak$nE)c=TraA}cd`<|DWuaRB$`5?D@wsBSy66E7ti!uMdI(zD$aHM-0@TJuiw zhsbpEUs>A#RK+TT660)+km+45-W@%PEBQ1zbpE>0_X#A)%JNNW3GwX;yL?JAit#Or z3uCtqB30K@DU{hxp~qU#>EY1<%$$pPAUXRaLLGtY-@GnU2HFBl8eh6nT2`1w!n7$h zr1#^fg40|RID@}NTwOIqI(W6kftmS=P+aEEk}X!=?q8}CzN-ovI@0tGcXM|r>!dtb zj3+lHm9cA82;v3IxV5kDtOpc~I$bPd9;jUM1sB7b&~?e`$5kzgl54^HheCzJp0`aP z?$7a&;*j~8=k=75J|6|Q+-P134LRY3&S=mXt`wI8K2`rtS$Mh+S~Kka$M3)w&aX>r zCe@j^m^ioQ-7Oa!P$lt&XXw@XUq}HB^&ry_y{i)W1q&P#!Et-ns&9WSnW@k*c2;J=4C*?_n$?S9SK=~TTc#PN zja|eZ9Lf}{8+cFpar=!!31r%NVgQ_}KqqSbrDV=|%2Gt=J=Bk2i9AdoMEKOu8%zyH zQAj0$pY~z_e-9ayJ_d}PTd#2U8=*g#@G;=pIm*tT&i!UdNEISlnKn;r?}hpL-`*-R zsmJI`AyUsSntQmGDBt@tje)zLX1?JQo86ks)DP16PbZ`d?B#nk(KDZZnRf2US!dex zG0!{6_&v~sDmUy_@$|0RV!=cqU*8fLp{?oFH9KII85ChBDkvWM4S{V*|Z`4Q-)IfDF462Hm-R{lj zWluD#2kt)p0IIF?;pyMhnv4&H^4RTIGww5vS<(m_T|Zsw__(#IZiQx_*RJ-Fnc%_! zJEf7dYUgTrYF)Bh*yiak{wDo@rW1{Ij!&1zbBB>v6uBSzvd7Se@`X9IjrweJA^H=o z@h{8YC(h>HBq&7S2GZJIp*YGIh6dw0lUv+)`U~Mrw#L(XU$;q2FBy}@xE}?;C|I&R zFoIF;cUKH&PX$K4W2l!o`K$eK;+){^_@UdeBVVAzbEzE8A>DR-7Yj&HFaDO|mGL1P z{WEJ$WaU~cn& zHxsMsldsiR=h}HYXk+-oBC|#r4-R+J#oX}0zn~$<%nJt(RQ9)&d{iU+1lP)FWy-$Y z!A0ff*=GN9NypN>q#EkqC!nrm(l*k&Sx3N}+>KmHcBJNaR0s+ogRooFId8p48c$QN z;nb6+;N82P^Pg|?&Y!uzbcK~vR^tvD>rP4)d1y9Ie-xWnI7_h9;s{6?Q*Qufe`&%t zTB%k>sHrQs#gQAV zzF;osY1Dn?M!pPvwC+Rp8f}mDQEoc4Bia1y>wMwtvB6OW^pUS8NXSE(ujgakN|JC4nO5z zSR)_`lRY>T{J^d)ShPXS(FSx~w(?lUX5KVA^4uP_vmZrz&~FxCb7TRcEXBNLp%-rc z{hg`c_@3*oEp_a`k^Tz=V*cr^mf2N&pF?@-&Ic5!EFjWqpPo-8X;ToY7LnrExbCh*pa zmMrbwuNczXl4Hp3T%(fKbSIyU`S&5)uckQBs_4mui5u>2gcVeETS%O44y+A z*8b$G1^Rjl^oas|Ju0O(3OgbFvDi!w0jUfrO^f0p0W-y>v<~Kt6QnGevPykSxQ=RD zP=UjhYkuc{>$~u3i28=-hf73vuA-QQvF!8V7t(s83|aRW$+^TYB#r8C&gkf^%`|vc z^y>zj>!)ycQq^Kj!+E}s_&js-Z7dD%@A6SB{wl1>wj&riFKHMeq$=N0{?$}nU0_EM z^wO+DPuY*uDlMl)xotxZ%)x^O1u@vJJJ`V=Zd(-YZtIcp(K8BoctBV=opy1@ZnXTY zMZJkYor0AP4>X0-zO+Wl*G^}P#*p@rc`*}3pB#oBeQyoqi$wzsS(MzK2FEVGF8*Gg5G@cEKYSJ~ z8GcN0=cA@oM5_1?)oyva!LQ--wYNa8+O6B<3eErj<+}&QI`4kHF2RO}`hch`u?hBwgKg?(yH-2})M1I(fb1 zapMIMyOUiiQk^*20yB3bMf*ER$>`DBCN|_Q`ObL z{QCKQp62~;rt_!El=#I@3LG5X;RBI7@q?AA-^xJk2h#>ugi2x(1{EpAFo zS&vBjvYBAY;rw!6-GG-};;(CIuX{>JpBJB>CqLI;u{nHDs8eBJ@OYoLg(G!1#M`XLBr-)9HQ|fs(~4hT?h&9b(K7g+0iB3mV3rt*~Q4L4+FyNBSXW zwqi&;;p1Y4Wipid`X$fhplYb#gv*OqK|ATHhRMTw)>x*t9Q#@McWz|s`Kt|eF06Zs zq1<7=KCCd$Nu}RBRloe}kScRXfx|@im5XjFw>X_-9diegj>%u_`$2Svib!NAeRT_R zd>=Y5U38G|G=VVG%5X@N2-C@8ZnCYjI0Km&r<6vdMyQC$SX4**->JortXD;7=jfH5 zr%O04Rgk!A-(2sMtMSpF#7EqUCF+kRmVNgpE2r%~`Bir=hffrX5wV)S`%nR(Eh@r| zw3;|Pw$k~XRi%Ke>Uo(6`zN*DHX?6Y@0*A3PgE$y__Xg8Jz){y^LtB;%F4}3DN~FN6iG|++-P3zxz%2GV=8Xk*4z8 z8TYx(l->nuQcjT?#<-Gl!ata&N6?0KpQ`~?c`7r*EK;U~Za!@(oj%hBsUg1j%i5o# zWwkP@J!ry;hn-2!_#5@{&$ir_bP^;$A&P42&az269}j5Ws{ZQ8=_vbQO|~oM5BbZ8 zJVnyj3W4%+ME9I3bn=ak%zXNXDFu8_C_5z*5LYl$0}xD1NWqZiI4u|ZEICBJa)4<}LDU*G3EvFYi-rHX1Q z=um38Q^9bFB>PRlgCnfzm-zfaQEm(%o{~S(3$|g9iL0B*_O%_^dAGuT2+PrTWQJuA z@09-|nsk1_daE(o|IO!x=hZjMXoe-OzDJ8MmlIiVA5zsiMdd0aV^lYi1C*)BJZS$v zB9L^3v;E7rFU;MYy>rrt1s}$+gpZr4a^L#WHhHu-m*FW_5{DWOA56NTy+em7edX`h z1&;1N%5r@T?VU699gQe8!#_(lbuK=!r&VxD@I~vjnoOdFf1bpbus=tO0ttN1Sy()^ z|G91QPUZqZDz_c0?;`O`Gr zv^AY$wA5z~Zu3s%T&aXmq<wyg;|;}t`xRaAQlc<~ ztB*PM!sSZMICv=Nz4dzl25;Xb74{ba8gGuQ(z!9!55vR_ZRH13rDBRElf z`o&!y@KRy`OM5428v|YmgiX`z!J0tCcL1OX6lZdJ2h;`C8h>;0#X}h|N`0Wx%n*ZU zu*t@Uh*0>+S3z;g8BohH!%fgeOD*0Qb?-`=leDh9p$j^jAMuF~)x}4E+W5oPq{;YA zr*Ie{lE>ovYhg6=p80&K3$pHQN-Cl=8nhYLd6YZ2uR_N;mgUzihr|i*+>*8CYCizn zU1mumNz^APOT|{iYe^~KCr9wkuGxG)9PL_VPtNYAc#<(OE(LKqbjigyg4FaIT6H6y8AM|S)&Rf4A#UR0ZH)W=)^KEpM1Vb z(&^L+8T%n!SVRI1kdkwMg4O+zPyeNeAy`>za$462HfLM1e0K1ZZbj_T=-Be$T+Ww>B($ zyWgHXWeU9PDP6h*-Us*vYt5L`Q{T|7(qn1XC5D>2j=|F_mvM_6t&DC(vbjWKxv>C! ziZyvP=3NHTCadcI6)`Rz#h>4Q>fveU-;!&mG>0`z! z=@+@@Q1SILx~ea4jf?A4THgDd@i|Jc0sL}Z>i)Uw>ghGL@}+%3@HrDF)2D*8wGd?}@k;8z(hkTjB3RIAh{ zE=PUjx!QcKLuPM~D3E$bsLH_k)ZXmDTAkfro0rlZU3E-T6+wod)o9 zjfkSO*V~}bfYiOK*oI3+E#--!OFrF6n|UA7H}l^AQ3A<)_YRJiOJY^{mqgq1R?yH` z_cHH&NFvRiW)r72@68-uWZcz3QfJmSN1r#+pWv(a<73VgUmRxbuY8P|ZOj$sM)3FnEL`$cRcWgnh6Q5XIv z74#{0fU-hZ(&RQaaV8NTYE8x=TI^Ecyuu+>{D1cNf@G9p6T7ycHVpjblxuGnFQRpK zh0(5+QYg7URUz;`nTL-KCf@%^l_=L4HtG>g(+-`J(EJPe<=+5`Yyv+!Gsj<+Encd5 zNOIT;BEA2K0O(h@=!;4^;SBI^19TPbvdK zUBv>&$cGwe9~Z`c6)V%k;beB*IPUnPv;QOuOKCqyqdO640=CmSv+>(B0cq(PiD``K zcRm4TzE%q&9VdJBV-CC2p| z=u1V%^@AU?YAk`CY3d;j*xZQPHQ53vF@$EA@gg)vl~R^875f^sDwVM^WpU*B3~BT` zyRf7Z4Nw1r&MPQX4lBn-RJ~Qx`^q7%U&qD3w?wX905hDhbbLT zD2Iw$@;D3>3F>$N literal 0 HcmV?d00001 diff --git a/docs/Images/readme/how-it-works.svg b/docs/Images/readme/how-it-works.svg new file mode 100644 index 0000000..d3a33d3 --- /dev/null +++ b/docs/Images/readme/how-it-works.svg @@ -0,0 +1,59 @@ + + + ProbeCrux pins first, then evaluates without mixing tiers + + + + + + + + + + + + PROBECRUX · PIN FIRST · THEN EVALUATE + + no network during a run + 17 rules · 3 tiers + + + + + repository + optional ref + acquireshallow clone, resolve toa concrete commit SHA + pinmanifest hash · advisory snapshotpattern set · toolchain · build id + scanone traversal → the shared index:files · items · spans · manifestsresolved dependency graph + + + ── all pins resolved before any rule runs ── + + evaluaterules are pure functions over the index · no I/O + + + + DETERMINISTIC14 rules · byte-identical on re-runships v1 + HEURISTIC2 rules · thresholds must be pinnedreproducible then · v2 + ADVISORY1 rule · model-assisted · v2not reproducible · own section · never merged + + + + + findings.jsondeterministic set + report.mdhuman-readable · tiered sections + receiptsigned · pins everything above + + + + + APPEND-ONLY RULE IDENTITYprobecrux.rules.yaml · blake3 manifest hash over the file with hash_excludes removed▸ deprecated_rules is never emptied + + + silence is never a pass; every rule that did not run says why. + diff --git a/docs/Images/readme/probecrux-dark.svg b/docs/Images/readme/probecrux-dark.svg new file mode 100644 index 0000000..e1c6328 --- /dev/null +++ b/docs/Images/readme/probecrux-dark.svg @@ -0,0 +1,11 @@ + + PROBECRUX wordmark for dark backgrounds + + + + + + + + + diff --git a/docs/Images/readme/probecrux-light.svg b/docs/Images/readme/probecrux-light.svg new file mode 100644 index 0000000..9afdbbf --- /dev/null +++ b/docs/Images/readme/probecrux-light.svg @@ -0,0 +1,11 @@ + + PROBECRUX wordmark for light backgrounds + + + + + + + + + diff --git a/docs/Images/readme/receipt.svg b/docs/Images/readme/receipt.svg new file mode 100644 index 0000000..aa1ac95 --- /dev/null +++ b/docs/Images/readme/receipt.svg @@ -0,0 +1,34 @@ + + + What a ProbeCrux receipt attests and does not attest + + + + + + + + + + WHAT THE RECEIPT SAYS · AND WHAT IT DOES NOT + verification stays offline + + + ATTESTSThese rules, at this version, were evaluatedagainst this commit at this time, andproduced this findings set. + DOES NOT ATTESTThat the repository is secure, correct, fitfor purpose, or free of defects outside thescope of these rules. + + + + projectpublic key published in keys/ · verify offlinewith no arrangementtamper-evidence, not attestation of a party + operatoryour own key · never generated and never held by ProbeCruxbinds findings to whoever controls itUSE FOR AN EVIDENCE OBLIGATION + + + if the configured key cannot be loaded, the run fails — there is no code path that invents one. + verification never fetches; the network can be given a different answer. + From 0bd420ed1b8d20b9bba3bb6d3d7b38f7c3f49f39 Mon Sep 17 00:00:00 2001 From: CueCrux-Myles Date: Wed, 5 Aug 2026 13:57:51 +0100 Subject: [PATCH 2/2] Correct the rule counts, and stop the diagrams shortening two claims MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The manifest holds eighteen rules, fifteen of them deterministic. The README still said seventeen and fourteen, and the previous commit hardened that into two SVGs — where it costs an image re-export to fix rather than a one-line edit. Corrected in the hero, the rule-set section, the tier table, the pipeline diagram and its alt text. The drift predates this branch: R018 was minted and R004 widened without the README following. Nothing tests the README's counts against the parsed manifest, which is precisely the failure R002 exists to detect — a document that has drifted is worse than no document, because it tells a reader the work was done. `crates/probecrux-manifest/tests/rules_manifest.rs` already asserts 18 and 15; only the prose was unguarded. Also corrects `docs/architecture.md`, which counted fourteen deterministic rules in its v1-scope section. Its per-rule ordering and deferral lists are left alone — those are scope decisions, not a count, and are not mine to guess at. receipt.svg was rendering `does_not_attest` without its last two sentences — "ProbeCrux reports findings for triage. It does not issue assurance." Those are the two doing the heaviest lifting, one naming what the tool is and the other the strongest disclaimer in the project, and a diagram is the worst place to shorten a string the manifest requires verbatim. Both panels are rewrapped to a common measure; the full wording now fits without changing the layout, and the aria-label carries it too. The pipeline diagram's badge now reads "no network during evaluation" rather than "no network during a run". Since D023 the container makes two calls around evaluation for the hosted input path, and it ships curl to do it. The narrower claim is the one that survives someone reading the Dockerfile. Co-Authored-By: Claude Opus 5 (1M context) --- README.md | 8 ++++---- docs/Images/readme/how-it-works.svg | 6 +++--- docs/Images/readme/receipt.svg | 6 +++--- docs/architecture.md | 2 +- 4 files changed, 11 insertions(+), 11 deletions(-) diff --git a/README.md b/README.md index c17c422..7f49f3b 100644 --- a/README.md +++ b/README.md @@ -13,7 +13,7 @@ ### Reproducibility is the product. **A Rust workspace audit that emits a signed, replayable receipt alongside its findings.** -Seventeen rules across three tiers, append-only identifiers, and a receipt that pins the +Eighteen rules across three tiers, append-only identifiers, and a receipt that pins the commit, the manifest hash, the advisory snapshot, the pattern set and the toolchain. Nothing is fetched during a run. Verification is offline. @@ -58,7 +58,7 @@ a blended total lets an unreproducible finding inherit the credibility of a repr one. ProbeCrux pipeline: a repository and optional ref are acquired to a concrete commit SHA, then the manifest hash, advisory snapshot, pattern set, toolchain and build id are pinned before any rule runs; a single scan traversal builds the shared index, rules evaluate as pure functions over it, and findings land in three separate tiers — 14 deterministic, 2 heuristic, 1 advisory — emitted as findings.json, report.md and a signed receipt over an append-only rule manifest + alt="ProbeCrux pipeline: a repository and optional ref are acquired to a concrete commit SHA, then the manifest hash, advisory snapshot, pattern set, toolchain and build id are pinned before any rule runs; a single scan traversal builds the shared index, rules evaluate as pure functions over it, and findings land in three separate tiers — 15 deterministic, 2 heuristic, 1 advisory — emitted as findings.json, report.md and a signed receipt over an append-only rule manifest"> More detail: [`docs/architecture.md`](docs/architecture.md). @@ -145,11 +145,11 @@ different answer by whoever controls the network, so ours does not fetch. ## Rule set -Seventeen rules across three tiers. +Eighteen rules across three tiers. | Tier | Count | Reproducible | Ships | |---|---|---|---| -| `deterministic` | 14 | Byte-identical on re-run | v1 | +| `deterministic` | 15 | Byte-identical on re-run | v1 | | `heuristic` | 2 | Only with thresholds pinned | v2 | | `advisory` | 1 | No — model-assisted | v2 | diff --git a/docs/Images/readme/how-it-works.svg b/docs/Images/readme/how-it-works.svg index d3a33d3..8a9f806 100644 --- a/docs/Images/readme/how-it-works.svg +++ b/docs/Images/readme/how-it-works.svg @@ -20,8 +20,8 @@ PROBECRUX · PIN FIRST · THEN EVALUATE - no network during a run - 17 rules · 3 tiers + no network during evaluation + 18 rules · 3 tiers @@ -38,7 +38,7 @@ - DETERMINISTIC14 rules · byte-identical on re-runships v1 + DETERMINISTIC15 rules · byte-identical on re-runships v1 HEURISTIC2 rules · thresholds must be pinnedreproducible then · v2 ADVISORY1 rule · model-assisted · v2not reproducible · own section · never merged diff --git a/docs/Images/readme/receipt.svg b/docs/Images/readme/receipt.svg index aa1ac95..28643d3 100644 --- a/docs/Images/readme/receipt.svg +++ b/docs/Images/readme/receipt.svg @@ -1,5 +1,5 @@ - + What a ProbeCrux receipt attests and does not attest @@ -20,8 +20,8 @@ verification stays offline - ATTESTSThese rules, at this version, were evaluatedagainst this commit at this time, andproduced this findings set. - DOES NOT ATTESTThat the repository is secure, correct, fitfor purpose, or free of defects outside thescope of these rules. + ATTESTSThese rules, at this version, were evaluated against thiscommit at this time, and produced this findings set. + DOES NOT ATTESTThat the repository is secure, correct, fit for purpose, orfree of defects outside the scope of these rules. ProbeCruxreports findings for triage. It does not issue assurance. diff --git a/docs/architecture.md b/docs/architecture.md index bc9e23e..7d04436 100644 --- a/docs/architecture.md +++ b/docs/architecture.md @@ -111,7 +111,7 @@ the format moves. ## v1 scope -Fourteen rules are marked `deterministic`. Not all of them ship in the first release — +Fifteen rules are marked `deterministic`. Not all of them ship in the first release — they differ by an order of magnitude in implementation cost, and the release is bounded by what can be built well rather than by what shares a tier.