Hello Node.js Release team,
I am documenting the provenance and validation policy for the official Node.js v26.5.0 checksum manifest. Could a releaser or release-infrastructure maintainer identify the authoritative, immutable sources for the following?
- Which release-infrastructure component generated SHASUMS256.txt for Node.js v26.5.0?
- What immutable repository commit, workflow revision, image identity, or equivalent release-infrastructure identity was used?
- What filename grammar does that generator intentionally emit?
- Are relative-path filename forms intentionally supported, or are entries required to be basenames?
- Which immutable revision of the official Node.js release-signing key set was applicable when v26.5.0 was released?
- Which official documentation or immutable source supports each answer?
For an answer to be usable as provenance evidence, please provide immutable links or identifiers tied specifically to v26.5.0 where available. If the relevant generator is private or its exact release-time revision cannot be established, confirmation of that limitation would also be useful.
This is a general release-process question. No manifest entry, checksum, filename, or private diagnostic information is being requested or disclosed.
Thank you.
Hello Node.js Release team,
I am documenting the provenance and validation policy for the official Node.js v26.5.0 checksum manifest. Could a releaser or release-infrastructure maintainer identify the authoritative, immutable sources for the following?
For an answer to be usable as provenance evidence, please provide immutable links or identifiers tied specifically to v26.5.0 where available. If the relevant generator is private or its exact release-time revision cannot be established, confirmation of that limitation would also be useful.
This is a general release-process question. No manifest entry, checksum, filename, or private diagnostic information is being requested or disclosed.
Thank you.