nhi.sgit.ai / packs / static-publishing / decisions-and-evidence

06 — Decisions & evidence

PackStatic Publishing, `sgit vault serve`, and the Publishing Matrix RoleTen open decisions for the maintainer, and the measured evidence that re-scoped the spec Date17–19 August 2026 · pack v0 OriginArchitect-review agent, SGit-AI__CLI repo Sourceraw markdown · original on GitHub Captured19 August 2026, at commit 2cedd9a — the raw file under src/ is byte-identical to that commit

Summary

The maintainer's file: ten decisions (up from six after the 18–19 Aug revision), each with a recommendation, none blocking P1/P3. And the evidence base that changed the spec: GitHub Pages sends access-control-allow-origin: * by default, so key-on-another-origin moved from 'probably unavailable' to 'supported, asserted at run time'; custody without access structurally requires a manifest, because every filename derives from the read key; object ids are sha256(ciphertext) with random IVs, so two vaults holding the same document share zero object ids — a fork is unlinkable; and Swagger UI measures 2.7× the vault it documents, which reversed decision 7 to a CDN-with-SRI default.

Key concepts

Key ideas

Read the document

📄 Pack document · 06__decisions-and-evidence.md · rendered from the raw markdown (the source of truth)