wintercount 0.1.0

Temporal policy provenance: pin the policy hash in force at every event, then answer 'what rules governed at time T' forever — named for the painted buffalo robes that recorded each year's defining event
Documentation
# Security policy

## Reporting

Open a private security advisory on the GitHub repository, or email the
maintainer (see `Cargo.toml` authors).

## Scope

In scope:

- `policy_at` returning a hash that was not actually in force at `ts`
  (ordering bugs in the count).
- Marks being mutated or reordered after painting.
- `foreign_marks` missing marks under unregistered policies.

Out of scope:

- Integrity of the source ledger — wintercount reads marks; anchoring
  them in a hash chain is the writer's/ledger's job.
- Confidentiality of policy documents — `PolicySet` stores the bytes
  it's given; protect them at the filesystem layer.

## Guidance

- Anchor the mark stream in a hash-chained or signed ledger so
  post-hoc repainting is detectable.
- Archive every policy document you pin a hash of — a resolvable
  registry is what turns a hash into evidence.