{"kind":"uds.sbom.diff","old":"v10","new":"v11","added":["pkg-11","pkg-238","pkg-58"],"removed":["pkg-154","pkg-217","pkg-230"],"unchanged_count":8,"honesty":"Package-level diff. Static-snapshot SBOM source; for live SBOMs feed the SPDX/CycloneDX docs. Deterministic given the version tags.","dsse":{"payloadType":"application/vnd.szl.uds.aggregate+json","payload":"eyJhZGRlZCI6WyJwa2ctMTEiLCJwa2ctMjM4IiwicGtnLTU4Il0sImhvbmVzdHkiOiJQYWNrYWdlLWxldmVsIGRpZmYuIFN0YXRpYy1zbmFwc2hvdCBTQk9NIHNvdXJjZTsgZm9yIGxpdmUgU0JPTXMgZmVlZCB0aGUgU1BEWC9DeWNsb25lRFggZG9jcy4gRGV0ZXJtaW5pc3RpYyBnaXZlbiB0aGUgdmVyc2lvbiB0YWdzLiIsImtpbmQiOiJ1ZHMuc2JvbS5kaWZmIiwibmV3IjoidjExIiwib2xkIjoidjEwIiwicmVtb3ZlZCI6WyJwa2ctMTU0IiwicGtnLTIxNyIsInBrZy0yMzAiXSwidW5jaGFuZ2VkX2NvdW50Ijo4fQ==","_dsse":"DSSEv1","_pae_sha256":"9fd3f534b7783d06fbf530d6cb1b100faa6082505df283bb831e7add2fd8bb6d","_signed_at":"2026-06-03T19:40:20.487692+00:00","signatures":[{"sig":"MEUCID5ZNB43Y05t/SBDcazPVxAWBSBxVToENWfp0Tk7umoEAiEAm4EQj8gqWjJKs9FE4133qx9/dHCnhJaFqNfEsXxgBtc=","keyid":"szlholdings-cosign"}],"signed":true,"honesty":"REAL — ECDSA-P256-SHA256 over DSSE PAE; verifiable by `cosign verify-blob --key cosign.pub` and by the /khipu/verify endpoint.","verify_key_url":"https://github.com/szl-holdings/.github/blob/main/cosign.pub"},"receipt_sha256":"393fe7ca99d0ae07e5e0e4e335b0c794e678b772e2cad9dd36f8c7dfa6b29036","signed":true,"doctrine":"v11 LOCKED"}