Use this index to find the maintained source of truth for each part of HeaderProof.
- Configuration — CLI/config behavior and safe defaults.
- CI integration — stdout/stderr, exit codes, JSONL, and SARIF contracts.
- Verifying releases — checksums, Cosign, and GitHub provenance.
- Testing evidence — controlled fixtures and measured limitations.
- Project proof — what the published evidence does and does not prove.
- Contributing — contribution workflow and detector-template guide.
- Architecture — engine, templates, evidence gates, and OOB boundaries.
- Roadmap — implemented roadmap state and remaining work.
- Discovery — public discovery and external-list distribution policy.
- Maintainer policy — review, attribution, integration, and release policy.
- Release process — release checklist and post-publish verification.
- PyPI publishing — Trusted Publishing setup and package publication.
- Security policy — vulnerability reporting and supported release policy.