Expand description
Bundle verification, in the order the trust chain requires.
The archive digest is checked before a single byte is parsed, the manifest signature before the manifest is believed, and the per-file checksums before the extracted tree is used. A bundle that fails any step is never installed and never cached: there is no warn-and-continue path here.
Copyright (c) systemprompt.io — Business Source License 1.1. See https://systemprompt.io for licensing details.