Admit
Fix the exact source, release, or artifact identity before work begins.
Independent clean-lab software assurance
If it was not proven, it does not pass.
WindAnvil takes an exact source or release, applies explicit policy outside the subject, preserves the receipts, and returns one honest outcome.
If the proof is missing, the result is BLOCKED. It never quietly becomes PASS.
A green build is not provenance. An SBOM is not proof of which build graph produced it. A skipped check is not a passing check.
WindAnvil keeps identity, policy, execution, observation, and decision separate so the final claim can be narrower and stronger.
Fix the exact source, release, or artifact identity before work begins.
Apply the external minimum policy and any additive local requirements.
Run authorized work without substituting source, architecture, or capability.
Collect results, hashes, provenance, and capability evidence as distinct facts.
Return PASS, FAIL, or BLOCKED. Never a stronger claim than the proof allows.
It binds the admitted object to the policy, execution plan, observations, artifact digests, and terminal verdict without inventing a second layer of interpretation.
immutableboundboundcanonicalsha256PASS | FAIL | BLOCKEDSmall upstream changes expose the authority boundaries WindAnvil cares about: release identity, dependency state, artifact binding, inherited policy, and build-graph semantics.
Merged upstream
Accepted changes only. Open proposals stay in the broader fieldwork layer until upstream merges them.
Narrower claims.
Stronger evidence.
No invisible gaps.