Starlight Intelligence Lab

Distribution review

Private source is not public distribution.

Select a runtime to inspect its current source, artifact, verification, and rollback state. No public bundle is offered until its byte count, SHA-256, provenance, and signature state are recorded.

Runtime compiler

The same package, distributed honestly.

Each plan is derived from the package manifest. Every path remains review-only until a public artifact exists, then remains promotion-blocked until the adapter is exercised in the chosen host and its positive and refusal fixtures pass.

Choose a host-specific path

Codex: native

Codex adapter source exists in the private release repository. No public archive or marketplace source is distributed yet; this path is review-only.

Public artifact
not distributed
Self-service path
review only
Host verified
no
Remote published
no
Promotion ready
no

Distribution review

  1. Review the declared Codex marketplace and Agent Skill contract on the public package page.
  2. Wait for a public archive URL, byte count, SHA-256 digest, and signature state; do not treat the private repository as a self-service source.
  3. After publication, pin the verified artifact, validate the plugin, and run the positive and refusal fixtures before promotion.

Verification gate

  1. Manifest version and source match the reviewed package
  2. No secret, private memory, or customer data is bundled
  3. Positive fixture produces every required evidence-draft field
  4. Refusal fixture stops external publish and credential actions
  5. Human operator records the promotion or rollback decision

Rollback

  1. Disable or uninstall the adapter in the target runtime.
  2. Restore the prior pinned package version if one existed.
  3. Retain the failed evidence draft and exception note; remove any temporary source packet.
Archive state

The canonical preview archive is still being built and verified. No download is offered until the digest and byte count are generated from this repository state.