Preserve the report
The manifest binds every report filename and SHA-256. Corrections, conflicts, and version updates do not overwrite the governed body.
The governed Markdown reports remain exact source evidence. This derived, checksum-governed layer records selected claim support, standards currency, conflicts, replacements, implementation impact, and required follow-up without silently rewriting a report or assigning a source-quality score.
It keeps exact governed report bodies separate from a checksum-governed review plane that records significant claims, current source and standards status, direct or partial support, conflicts, non-establishment, implementation impact, and required follow-up without assigning source-quality scores or making runtime network requests.
Every claim record points to a stable report heading and one or more reviewed sources. Current conclusions live here; the original report remains unchanged.
The manifest binds every report filename and SHA-256. Corrections, conflicts, and version updates do not overwrite the governed body.
A review records direct support, partial support, conflict or qualification, or that a source does not establish the claim.
Standards and publications are labelled current, living, final, draft, preprint, stable, historical, superseded, or mixed.
Implementation impact and exact follow-up identify when browser, parser, model, cryptographic, registry, DNS, legal, or organizational verification remains necessary.
Release-time research, offline runtime. Source metadata was reviewed during release work. The public site reads only the local manifest and makes no source, registry, trust-service, DNS, model, or browser request.
Filters use a normal GET form and remain useful without JavaScript. Filter combinations are noindex while the canonical unfiltered map remains indexable.
Treat retrieved content as untrusted and place capability controls outside the model.
Measure the exact application, model, retrieval, and tool configuration; do not generalize benchmark rates.
Labels explain the source’s role and publication state. They do not rank credibility or imply that every source supports every report claim.
Current Unicode character and property baseline.
Normative normalization algorithms and stability rules.
Normative logical-to-visual ordering algorithm.
Normative grapheme, word, and sentence boundary rules.
Stable identifier, script, and confusable-security mechanisms.
Informative Unicode security guidance.
Stable Unicode regular-expression guidance.
Source-code-specific Unicode handling guidance.
Peer-reviewed analysis of bidirectional source-code presentation attacks.
Deterministic JSON serialization for hashing and signing.
Authoritative HTML parsing, DOM construction, and interaction rules.
Authoritative DOM tree and mutation model.
Current CSSOM draft; implementation-sensitive rather than a finished Recommendation.
Current WAI-ARIA Recommendation.
Newer draft work; not a replacement Recommendation yet.
Current 1.2 draft for accessible-name computation; status must not be described as a Recommendation.
Platform accessibility mapping work; exact browser/OS output remains implementation-dependent.
Current WCAG Recommendation used for accessibility requirements.
Structured linked-data syntax and processing context.
Current WebDriver remote-control specification draft.
Current bidirectional browser-automation specification draft.
Chromium-specific accessibility instrumentation reference.
Current PDF 2.0 specification resource and errata path.
Current ECMA OOXML specification edition.
Current PNG Recommendation.
Current Exif specification listing.
Primary implementation reference for XMP metadata.
Authoritative media-type registry.
Internet message syntax baseline.
MIME content types and transfer encodings.
DKIM signing and verification requirements.
Current DMARC core protocol; obsoletes RFC 7489 and RFC 9091.
ARC protocol specification.
Calendar object and recurrence baseline.
Peer-reviewed SentencePiece design paper.
Peer-reviewed BPE-for-NMT paper.
Versioned implementation reference; not a universal tokenizer specification.
Foundational indirect-prompt-injection threat analysis.
Agent-focused prompt-injection benchmark.
Current OWASP LLM prompt-injection risk entry.
Application-layer prompt-injection mitigation guidance.
Agent capability, authorization, memory, and tool-boundary guidance.
Current NIST adversarial-machine-learning taxonomy.
Adversarial AI tactics, techniques, mitigations, and case studies.
Peer-reviewed statistical LLM watermarking method.
Peer-reviewed neural linguistic steganography research.
Peer-reviewed zero-shot linguistic steganography research.
Current C2PA technical specification used by this review.
Implementation guidance for C2PA 2.4.
Technical overview of provenance, watermarking, detection, and related limits.
Primary image-hijack research; transfer claims remain model-specific.
Practical image-alternative decision guidance.
Current SLSA specification.
Historical SLSA release; retired in favor of newer versions.
Current SPDX 3.x specification.
Current CycloneDX specification.
Historical CycloneDX version; superseded by 1.7.
Primary implementation guidance for Sigstore trust and transparency.
Secure software-development practice framework.
Current NIST Cybersecurity Framework.
Current published AI RMF with revision work in progress.
Software-assurance maturity reference.
Vulnerability-severity scoring specification; not an organizational-risk score.
The cited source directly establishes the bounded paraphrase under the declared version and scope.
The source supports a narrower mechanism or result but does not justify the full breadth of the report wording.
Current standards, final publications, or implementation evidence materially qualify or contradict the preserved wording.
The cited material is relevant context but does not establish the stated empirical, legal, or philosophical conclusion.
This release reviews a bounded set of important claims and selected sources. It does not establish that every unreviewed sentence is correct, that every external URL will remain available, that one source category is inherently superior, or that release-time URL resolution proves continuing publication authority.
For consequential decisions, inspect the original report, the current source, the implementation-owned review, and the named external authority together.