HashSeal build plugins

Thin adapters that shell to the hashseal CLI. Plugins do not re-implement seal/check algorithms.

Part of the Build tools product line (tree / release / CI). For instruction files, see Agent instruction file integrity seal.

Signed, Sealed, Delivered - I’m Yours.

PATH / binary requirement

Variable Purpose
PATH Must include hashseal (or hashseal.exe on Windows)
HASHSEAL_BIN Optional absolute path override

Build from monorepo:

cargo build -p hashseal --release
# target/release/hashseal[.exe]

Tiny verify-only binary (no clap/serde):

cargo build -p hashseal-check --release

Install story: docs/install.md.

Matrix

Plugin Path Status
npm plugins/npm Skeleton — hashseal-npm + JS API
Maven plugins/maven Skeleton — seal / check / verify goals; Central via java/ (-Pcentral, server hashseal-central)
Gradle plugins/gradle Skeleton — hashsealSeal / Check / Verify (includeBuild)
Cargo plugins/cargo Aliases + docs (no separate crate)
Python plugins/python Reserved / empty
Go plugins/go Reserved / empty

Zero-dep verify SDKs (not plugins)

For in-process digest check without the CLI:

Lang Path Runner
JS verify/js node test/vectors.test.js
Python verify/python python test/test_vectors.py
Java verify/java javac + RunVectors
Go verify/go go test . / go run ./test/
Ruby verify/ruby ruby test/run_vectors.rb (pure blake3)
.NET verify/dotnet dotnet run --project Hashseal.Verify.Test (pure blake3)

Vectors: verify/vectors/instruct-v1.json (FULL canonical mode).

IDE: extensions/vscode (PATH / HASHSEAL_BIN / HASHSEAL_CHECK_BIN).

Packaging notes

See docs/install.md, docs/packaging.md, and .github/workflows/release-binaries.yml.

Copyright (c) 2026 MonkeyKing.dev