Metadata-Version: 2.4
Name: jep-core-conformance
Version: 0.7.6
Summary: JEP Core 0.7 conformance tools with explicit legacy 0.6 compatibility
License-Expression: BSD-3-Clause
Project-URL: Homepage, https://github.com/hjs-spec/jep-core
Project-URL: Documentation, https://github.com/hjs-spec/jep-core/blob/main/docs/IMPLEMENTER-GUIDE.md
Project-URL: Specification, https://datatracker.ietf.org/doc/draft-wang-jep-judgment-event-protocol/
Project-URL: Issues, https://github.com/hjs-spec/jep-core/issues
Requires-Python: >=3.10
Description-Content-Type: text/markdown
License-File: LICENSE
License-File: LICENSING.md
License-File: licenses/IETF-CODE-COMPONENTS.txt
Requires-Dist: PyNaCl<2,>=1.6.2
Requires-Dist: cryptography>=42
Requires-Dist: rfc8785==0.1.4
Provides-Extra: test
Requires-Dist: pytest>=8; extra == "test"
Requires-Dist: jsonschema>=4.18; extra == "test"
Dynamic: license-file

# JEP Core

The canonical source for **Judgment Event Protocol**: signed statements of Judgment (J), Delegation (D), Termination (T) and Verification (V).

Core defines event structure and observable checks. It does not decide truth, authority, legal effect, causality, policy or external consequences. JEP is an individual Internet-Draft, not an IETF-endorsed standard.

## Install the validator

In a fresh Python environment:

```sh
python -m pip install jep-core-conformance==0.7.6
jep-validate --help
jep-validate validate event.json --keys keys.json
```

`event.json` must be the actual event and `keys.json` the verifier's key map; use the [local create/export/verify example](https://github.com/hjs-spec/jep-agent-sdk#local-create--export--independent-verification) to generate synthetic sample files. Demo-supplied public keys establish signature consistency, not independently trusted actor identity. No hosted API or account is required.

Do not install historical `jep-v06-conformance-seed` alongside this package: they share the `jep_conformance` import namespace. The current package already includes the explicit `jep-validate-06` compatibility command. Existing old environments and signed archives are not silently migrated.

## Start here

| Task | Entry |
|---|---|
| Understand Core 0.7 in one page | [Current overview](https://github.com/hjs-spec/jep-core/blob/main/docs/ONE-PAGE-OVERVIEW.md) |
| Select exact Core / Profiles / Conformance publications | [Specification sources](https://github.com/hjs-spec/jep-core/blob/main/docs/SPECIFICATION-SOURCES.md) |
| Read the published protocol | [Frozen Internet-Draft -07](https://github.com/hjs-spec/jep-core/tree/main/releases/draft-07/) |
| Read the working source | [Editor's Copy](https://github.com/hjs-spec/jep-core/blob/main/draft-wang-jep-judgment-event-protocol.md) |
| Implement or migrate | [Implementer guide](https://github.com/hjs-spec/jep-core/blob/main/docs/IMPLEMENTER-GUIDE.md) · [0.7 migration](https://github.com/hjs-spec/jep-core/blob/main/docs/MIGRATION-0.7.md) |
| Create, export and independently verify locally | [Agent SDK local example](https://github.com/hjs-spec/jep-agent-sdk#local-create--export--independent-verification) |
| Try a locally hosted HTTP API | [HTTP Quickstart](https://github.com/hjs-spec/jep-quickstart) |
| Choose a client or recorder | [Integration directory](https://github.com/hjs-spec/.github/blob/main/PROJECTS.md#integrate) |
| Understand component boundaries | [Architecture](https://github.com/hjs-spec/jep-core/blob/main/docs/architecture/README.md) |
| Test your own implementation | [BYOI conformance path](https://github.com/hjs-spec/jep-core/blob/main/docs/BYOI-CONFORMANCE.md) · [Report format](https://github.com/hjs-spec/jep-core/blob/main/docs/INTEROPERABILITY-REPORT.md) |
| Contribute or report a vulnerability | [Contributing](https://github.com/hjs-spec/jep-core/blob/main/CONTRIBUTING.md) · [Private security reporting](https://github.com/hjs-spec/jep-core/blob/main/SECURITY.md) |

## Current contract

**Core 0.7 · wire major `jep: "1"` · published 2026-09-26.**

- Event Identity `(who,id)` identifies an event; Event Hash identifies an exact signed artifact.
- Acceptance is idempotent per Event Identity within an acceptance domain.
- Validation reports independent checks and `valid`, `invalid` or `indeterminate`.
- Freshness mechanisms belong to profiles; Core does not require a nonce.
- Chain reconstruction, delegation enforcement and termination cascade belong to companion/application layers.

The published -07 snapshot is immutable. Its exact RFCXML and SHA-256 are recorded in the [freeze record](https://github.com/hjs-spec/jep-core/blob/main/releases/draft-07/README.md). Later changes belong to the Editor's Copy and a subsequent draft. [Datatracker](https://datatracker.ietf.org/doc/draft-wang-jep-judgment-event-protocol/) is the external publication record.

## Develop and test from source

Clone this repository before using the source-only commands below:

```sh
git clone https://github.com/hjs-spec/jep-core.git
cd jep-core
python -m pip install -e '.[test]'
make validate conformance repository-check
python -m pytest
```

The default Python validator, schemas and manifest target Core 0.7. [Validator usage](https://github.com/hjs-spec/jep-core/blob/main/reference-validator/README.md) explains keys and acceptance storage.

## Current and historical assets

| Current | Historical compatibility |
|---|---|
| Core `-07`; Profiles `-01`; Conformance `-02` | Core `-06`; profiles/conformance `-00` |
| `test-manifest-0.7.json`, Python `jep_validate_07.py` | `test-manifest-0.6.json`, Python `jep_validate.py` |
| Versioned 0.7 schemas and vectors | Go and TypeScript validators currently support **0.6 only** |

Schemas and tools are implementation aids; the applicable specification controls normative requirements. Use `make conformance-legacy` only for known 0.6 artifacts. Never select a legacy decoder because current validation failed, or rewrite a historical signed artifact.

[Documentation index](https://github.com/hjs-spec/jep-core/blob/main/docs/README.md) · [Versioning](https://github.com/hjs-spec/jep-core/blob/main/docs/VERSIONING.md) · [Logging comparison](https://github.com/hjs-spec/jep-core/blob/main/docs/comparisons/logging.md) · [Current delivery status](https://github.com/hjs-spec/.github/blob/main/DELIVERY-CURRENT.md)

The repository was previously named `jep-v06`. Repository identity is now stable; protocol drafts and software packages have separate versions. Maintainer-operated production API hosting is deferred; self-hosting remains optional.

## External implementation testing

Software 0.7.6 includes the BYOI runner. It exports a self-contained signed suite
and runs a producer, verifier or acceptance adapter without companion repositories.
Reports disclose actual coverage and do not claim certification. See the
[installation and adapter contract](https://github.com/hjs-spec/jep-core/blob/main/docs/BYOI-CONFORMANCE.md).

## Licensing

Original implementation code and implementation aids use [BSD-3-Clause](https://github.com/hjs-spec/jep-core/blob/main/LICENSE).
Internet-Draft text, extracted Code Components and third-party material retain
their applicable terms. Read the [licensing scope](https://github.com/hjs-spec/jep-core/blob/main/LICENSING.md) before reuse.
