Build tools
Second HashSeal product line: seal and verify source trees and release artifacts so multi-step and multi-agent CI cannot silently rewrite what you ship.
Instruction-file seals live under Agent instruction file integrity seal — same core, different object.
What they are
| Capability | What you get |
|---|---|
| Tree seal | Ledger of digests for configured paths |
| Release bundle | hashseal-bundle/ — ledger, report, MANIFEST, optional artifact digests |
| Verify | Re-walk vs ledger; list every drifted path |
| Plugins | npm / Maven / Gradle / Cargo shells to the hashseal CLI |
| Config | JSON overlay .hashseal.json (no TOML crate) |
How they work
- Configure includes/excludes and options (example:
config/examples/hashseal.mvp.json). hashseal seal --treewrites the ledger;--releasestageshashseal-bundle/.hashseal verifychecks the tree (and optional bundle).- Plugins only invoke the CLI — algorithms stay in
hashseal-core.
hashseal seal --tree --release --root .
hashseal verify --root .
# Combined with instruction seals:
hashseal seal --instruct --tree --release --root .
Official tree vectors: verify/vectors/tree-v1.json.
How to use in CI / projects
- Install
hashsealon the runner (or setHASHSEAL_BIN). - Seal after the tree is in the state you intend to protect (or at release packaging time).
- Verify in a later job or before publish.
- Optionally wire a build plugin so
npm/ Maven / Gradle goals shell to the same binary.
Stack — docs per tool
| Tool | Repo path | Documentation |
|---|---|---|
| Full CLI | rust/hashseal |
CLI reference · Install |
| Core | rust/hashseal-core |
Algorithms for tree + instruct |
| Tiny check binary | rust/hashseal-check |
Instruct-only; optional for gates (see install) |
| npm plugin | plugins/npm |
npm README · plugins hub |
| Maven plugin | plugins/maven |
Maven README |
| Gradle plugin | plugins/gradle |
Gradle README |
| Cargo aliases | plugins/cargo |
Cargo README |
| Python / Go plugin slots | plugins/python, plugins/go |
Reserved |
| Packaging / GH Releases | scripts/, .github/workflows/ |
Packaging |
| Demo fixture | fixtures/mvp-demo |
fixture README |
Plugin matrix (summary)
Plugins require hashseal on PATH or HASHSEAL_BIN. They do not embed binaries.
See Build plugins for PATH setup and status per language.
Related
- CLI —
seal --tree,--release,verify,clean - Signing — GPG for instruct seals (tree path may grow attestation later)
- Agent instruction file integrity seal — document seals for agents
Copyright (c) 2026 MonkeyKing.dev