Skip to content

Repository files navigation

Sealr

CI

One archive. One meaning. One verified tree.

Sealr turns an untrusted archive into a verified, reusable tree capability. It chooses one explicit interpretation, verifies every member, and returns an evidence receipt. If verification fails, no tree is published.

Downstream tools consume the VerifiedArchive capability or materialized tree. The original archive can be deleted after admission, so another parser cannot silently give the same bytes a different meaning.

Get started · Documentation · Roadmap · Releases

Try it

Download the native Linux, macOS, or Windows archive from v0.1.0-alpha.17 and verify the release before running it.

# Inspect. View JSON goes to stdout; receipt JSON goes to stderr.
./sealr path/to/archive.zip

# Publish the verified tree into a new destination.
./sealr path/to/archive.zip --dest ./out

ZIP32 is the default. Select ZIP64 explicitly with --format zip64. The destination must be new and its parent must already exist. Exit 0 means verified, 2 means not admitted, and 3 means a failed destination effect.

To build from source, the repository pins Rust 1.98.0:

git clone https://github.com/blisspixel/sealr.git
cd sealr
cargo run --locked -p sealr-cli -- path/to/archive.zip

The getting started guide covers source builds, canonical evidence verification, and a Rust example that deletes the source before evaluating a wheel.

See it work

Inspecting a two-member ZIP verifies both members without writing a destination:

Linux terminal summary of Alpha.17 verifying two ZIP members with no destination written.

This is a rendered summary of verified CLI output. The full walkthrough includes parent-path rejection, materialization, both themes, and reproduction instructions.

Current status

Alpha.17 contains machine-readable publisher failures, tested evidence and Rust consumer migrations, named durability controls, and reproducible assurance bookkeeping. Native CI covers Linux, macOS, and Windows. The release notes describe the contents; the release page records publication state.

Sealr is a development preview for integration and adversarial testing. It has no independent security audit or stable production release. Receipts are unsigned, and admission does not establish that a program is safe to execute. This GitHub-only prerelease does not publish a crate to crates.io.

Alpha.17 starts the current owner-controlled distribution history. Earlier remote releases and tags are retired; their notes and measurements remain historical records. See distribution history.

The implementation and security boundary describes supported formats, the explicit Linux worker, resource limits, and open gaps.

What comes next

Measure source hashing, plan validation, worker setup, and payload work separately before changing the repeated-read boundary. A controlled downstream Alpha.15 experiment found a large difference for one small retained working set, but cannot attribute it to one internal phase. Lifecycle recovery and coordinated dependency maintenance follow; additional formats remain deferred. The iteration record preserves the historical artifact pins, exact measurements, and completed migration evidence.

The roadmap and execution plan use automated acceptance criteria without human approval or adopter recruitment dependencies. The owner-maintained validation project provides real-wheel integration evidence. The optional pilot contract defines independent adoption separately; automated conformance does not establish adoption or an independent audit.

Go deeper

Apache-2.0. Native archives include dependency license notices.

About

Safely extract untrusted ZIP/TAR archives or publish nothing. Strict Rust parsing, sandboxed workers, independent verification, and adversarial testing.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages