A specification and CLI for publishing, signing, verifying, rotating, and revoking trusted mirror URL metadata, including authenticity, expiry, sequence, and revocation information.
A Go CLI that evaluates whether a mirror is operationally ready, current, trusted, and safe to announce, including signed-manifest compatibility, expiry, revocation, and publication-safety checks.