vanta-lock — the vanta.lock model, canonical serialization, and the
manifest↔lock reconcile.
The lock pins exact versions and per-platform artifact hashes for every
target so a single committed file reproduces on any OS. See
docs/11-reproducibility.md and docs/31-lockfile-and-manifest-reference.md.
Serialization is canonical (sorted tools, sorted platform keys) so the file
diffs cleanly in VCS.