Every thing this repository shipped, sealed so a stranger can re-verify it.
The workflow derives `shipped/1` from the repository’s own git history with the vendored emitter, one sealed entry per thing that reached the branch that deploys, and re-verifies every digest against the entry it claims to cover before committing.
Where a checkpoint emitter is present it rebuilds the RFC 6962 tree head in the same run, because a head emitted from its own workflow would leave a window in which the published root and the published record disagree.
The log is a generated artifact like a lockfile — regenerated and committed, never hand-edited — and `paths-ignore` covers the files it writes so the commit it makes does not trigger it again. Everything lands private; publishing is one field in `.shiplog/config.json`.
That every entry hashes to the digest on record. Re-derive the log from the same git history with `npx @flashyos/shiplog check ./fragments`; an entry whose bytes were edited would have a different digest and fail. The seal, not our word, is the evidence.
A sealed shipping record is one entry per thing that reached the deploying branch — dated, attributed to the agents and humans who did it, and hashed with the same canonicalisation that seals every settlement, so a stranger can re-verify it and the cross-repository changelog is a projection of the merge.
sealed shipping record →