Build tools

Second HashSeal product line: seal and verify source trees and release artifacts so multi-step and multi-agent CI cannot silently rewrite what you ship.

Instruction-file seals live under Agent instruction file integrity seal — same core, different object.

What they are

Capability What you get
Tree seal Ledger of digests for configured paths
Release bundle hashseal-bundle/ — ledger, report, MANIFEST, optional artifact digests
Verify Re-walk vs ledger; list every drifted path
Plugins npm / Maven / Gradle / Cargo shells to the hashseal CLI
Config JSON overlay .hashseal.json (no TOML crate)

How they work

  1. Configure includes/excludes and options (example: config/examples/hashseal.mvp.json).
  2. hashseal seal --tree writes the ledger; --release stages hashseal-bundle/.
  3. hashseal verify checks the tree (and optional bundle).
  4. Plugins only invoke the CLI — algorithms stay in hashseal-core.
hashseal seal --tree --release --root .
hashseal verify --root .
# Combined with instruction seals:
hashseal seal --instruct --tree --release --root .

Official tree vectors: verify/vectors/tree-v1.json.

How to use in CI / projects

  1. Install hashseal on the runner (or set HASHSEAL_BIN).
  2. Seal after the tree is in the state you intend to protect (or at release packaging time).
  3. Verify in a later job or before publish.
  4. Optionally wire a build plugin so npm / Maven / Gradle goals shell to the same binary.

Stack — docs per tool

Tool Repo path Documentation
Full CLI rust/hashseal CLI reference · Install
Core rust/hashseal-core Algorithms for tree + instruct
Tiny check binary rust/hashseal-check Instruct-only; optional for gates (see install)
npm plugin plugins/npm npm README · plugins hub
Maven plugin plugins/maven Maven README
Gradle plugin plugins/gradle Gradle README
Cargo aliases plugins/cargo Cargo README
Python / Go plugin slots plugins/python, plugins/go Reserved
Packaging / GH Releases scripts/, .github/workflows/ Packaging
Demo fixture fixtures/mvp-demo fixture README

Plugin matrix (summary)

Plugins require hashseal on PATH or HASHSEAL_BIN. They do not embed binaries.

See Build plugins for PATH setup and status per language.

Copyright (c) 2026 MonkeyKing.dev