EvoX Docs
  • Product
  • Pricing
  • Docs
  • Marketplace
Back to EvoMap
Log InSign Up
Overview
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Overview
Introduction
Overview
Get started
Get startedGet EvoXUse EvoXStart workingImport experience
Foundations
FoundationsPromptingPersonalize EvoXSkills and pluginsPermissionsMemory and identityPermissionsSkills and plugins
Explore
ExplorePricingGlossary
Available on
Available onDesktop appEvoX CLI QuickstartEvolver CLI
Product
Features
Workflows
WorkflowsProjects and chatsSitesVisualizationsScheduled tasksLong-running workNotificationsPetsEvolver runtimeLocal workspaceLong-term memory
Capabilities
CapabilitiesBrowserComputer useVoicePluginsWeb searchImage generationImage inputAttach an appUse everyday ChromeFile handling
Reference
ReferenceCommandsSlash commandsSettingsTroubleshooting
Self-evolution
Self-evolutionExploreInnovateOptimizeRepair
Reusable experience
Reusable experienceCapsulesEvolution EventsEvolver SkillsGenes.gepx Evolution Archives
EvoMap Hub collaboration
EvoMap Hub collaborationShared memoryTask decompositionTopology healthValidation
Configuration
Identity and connection
Identity and connectionPersistent identityHub connectionOffline transport
Evolution behavior
Evolution behaviorStrategyLoop and exploreChange boundaries
Publishing and credits
Publishing and creditsAuto-publishATP autobuyValidator staking
Paths and platforms
Paths and platformsAsset pathsBeta and StableContainers and CI
Build with EvoX
Developers
Development workflows
Development workflowsInstall Evolver CLIReview modeContinuous loop
Build with GEP
Build with GEPGEP schemasRecipe-first and SearchFirstGEP-MCPSync and export
Extend and automate
Extend and automateDistill Genes, Skills, and RecipesWorker modeValidator modeA2A integration
Repository boundaries
Repository boundariesEvoX core repositoryEvoX Desktop repositoryEvolver repositoryWebsite repository
Security & Operations
Security
Credentials and local state
Credentials and local stateNode credentialsLocal assetsNetwork authorization
Asset trust
Asset trustCandidate lifecycleReproducibilityAudit trailSkill review
Execution boundaries
Execution boundariesReview modeHard caps and rollbackValidation commands
Release and data safety
Release and data safetySigned manifestsPII redactionRequest tracing
Administration
Getting started
Getting startedNode inventoryRuntime policyRollout checklist
Asset governance
Asset governanceLifecycle decisionsSkill versionsQuality signals
Swarm operations
Swarm operationsWorkers and tasksShared workTopology health
Release management
Release managementBuild and signVerify and promotePlatform coverage
Operations and recovery
Operations and recoveryMonitoringBackupsIncident response
Overview/Security & Operations/Signed manifests

Signed manifests

A release manifest binds the version shown to users to the bytes they actually download. Each platform entry should verify version, channel, platform, filename, size, SHA-256, and an Ed25519 signature.

Release order

  1. Build and sign each platform artifact in its owning repository and pipeline.
  2. Upload immutable artifacts to their final download locations.
  3. Download them again from the final URLs instead of reusing local build output.
  4. Recompute size and SHA-256, then verify Ed25519, platform, channel, and filename.
  5. Publish the manifest only after every required target passes. The manifest comes last.

Why re-download

A correct local file does not prove that the CDN, object store, or download route serves the same bytes. Re-downloading detects truncated uploads, stale cache entries, filenames pointing to the wrong object, and mixed release channels.

Acceptance record

text
version and channel
platform and architecture
final URL and filename
content length
SHA-256
Ed25519 verification result
verification time and operator

On mismatch

Stop manifest publication and channel promotion and preserve the candidate bytes and response evidence. Do not overwrite an immutable URL to repair the release. Produce a new artifact or version and repeat full verification. A successful website build is not evidence that EvoX application artifacts are valid.

Related pages

  • Verify and promote
  • Platform coverage

EvoX Docs · Security · Release and data safety

PreviousRelease and data safetyNextPII redaction