Deterministic DAG-CBOR codec for authoritative, cryptographically signed data.
The decoder is strict by construction: it rejects non-canonical
integers, indefinite-length items, floats, tags, out-of-order map keys,
and trailing bytes, so a given value has exactly one accepted encoding.
Decoding untrusted input is bounded in input size, memory, and stack
depth — container length prefixes are checked against the remaining input
before any allocation, and nesting is capped at [MAX_NESTING_DEPTH] — so
neither a crafted length nor pathological nesting can drive an
out-of-memory or stack-overflow abort.