Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 4 additions & 4 deletions public/llms.txt
Original file line number Diff line number Diff line change
Expand Up @@ -68,16 +68,16 @@ Current packages: crates.io Traverse at 0.14.0; npm `traverse-embedder-web@0.14.
- [Changelog](https://traverse-framework.com/changelog.html): release-by-release history.
- [Security & Permanence Audit](https://traverse-framework.com/security-audit.html): every known finding, its GitHub ticket, and its real status — not a marketing page.
- [FAQ](https://traverse-framework.com/faq.html) and [Questions](https://traverse-framework.com/questions.html): 70+ specific Q&A pages, mostly long-tail but accurate.
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); native+web+Swift ExactModelHost execute (swift-host-v0.14.0-1 / #1579); Kotlin/.NET not yet (first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; exact-ref execute native+web+Swift ExactModelHost; Kotlin/.NET not yet — no claimed ONNX generic runner.
- [Which hosts run signed exact-ref models?](https://traverse-framework.com/questions/which-hosts-run-signed-exact-ref-models.html) · [Is production model signing ready?](https://traverse-framework.com/questions/is-production-model-signing-ready.html) · [Can Kotlin or .NET run exact-ref yet?](https://traverse-framework.com/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.html): honest matrix (native+web+Swift ExactModelHost; Kotlin/.NET #1580/#1602); test-only key ≠ prod (#1567).
- [What is exact-ref model execution?](https://traverse-framework.com/questions/what-is-exact-ref-model-execution.html): discover → execute → trace; one shared `runtime.wasm`; signed schema `2.0.0` + `model.sig.json`; host-owned trust; `digits-mlp-1.0.0` (test-only key; prod signing #1567); published exact-ref execute is native + web + Swift ExactModelHost (`swift-host-v0.14.0-4` / #1579); Kotlin and .NET ExactModelHost are on main (#1580, #1602 closed) and are not in Maven/NuGet 0.14.0 (next cuts #1651; first landed in v0.12.0). Embedder notes: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) · [Release](https://github.com/traverse-framework/traverse/releases/tag/v0.14.0) · [Announcement #1576](https://github.com/orgs/traverse-framework/discussions/1576).
- [How do hosts trust signed models?](https://traverse-framework.com/questions/how-do-hosts-trust-signed-models.html): discover → execute → trace; one shared `runtime.wasm`; host-owned trust roots gate `register_package`; pin by digest + `model.sig.json`; test-only digits-mlp key; published exact-ref execute is native+web+Swift ExactModelHost (`swift-host-v0.14.0-4`); Kotlin and .NET ExactModelHost are on main, not in the published 0.14.0 packages (#1651) — no claimed ONNX generic runner.
- [Which hosts run signed exact-ref models?](https://traverse-framework.com/questions/which-hosts-run-signed-exact-ref-models.html) · [Is production model signing ready?](https://traverse-framework.com/questions/is-production-model-signing-ready.html) · [Can Kotlin or .NET run exact-ref yet?](https://traverse-framework.com/questions/can-kotlin-or-dotnet-embedders-run-exact-ref-yet.html): discover → execute → trace; one shared `runtime.wasm`; published exact-ref is native + web 0.14.0 + Swift `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main (#1580, #1602 closed) and not in Maven/NuGet 0.14.0 (#1651); test-only key ≠ prod (#1567).
- [What is digits-mlp?](https://traverse-framework.com/questions/what-is-digits-mlp.html): first trained exact-ref package in v0.14.0 (UCI digits MLP, 96.10% held-out, bit-identical); test-only signing; not a general LLM.
- [Does the website use the latest traverse-embedder-web?](https://traverse-framework.com/questions/does-the-website-use-the-latest-traverse-embedder.html): site pins `^0.14.0` (matching npm) and `/discover` admits its signed demo fixture through `registerPackage`; the site can lag future releases, so product apps pin published packages, not the website demo.
- [How does Traverse complement Hugging Face?](https://traverse-framework.com/questions/how-does-traverse-complement-hugging-face.html): Hub = provenance; Traverse = pinned signed client-first capability; not Transformers.js/Hub replacement; no defer promise until a second executor exists.

## Optional

- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; native+web+Swift ExactModelHost exact-ref; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Blog](https://traverse-framework.com/blog.html): engineering write-ups, dated — treat as historical snapshots, not current-state claims. Latest: [You don't edit a published capability. You mark it.](https://traverse-framework.com/blog/you-dont-edit-a-published-capability.html) (deprecation and revocation leave the contract in place; ranges skip the marker; exact pins in `traverse-registry` 0.27.0 still resolve with lifecycle status, registry#632, #631 closed; runtime refusal is traverse#1598, not shipped in v0.14.0). Also: [Model rights are data, not a README](https://traverse-framework.com/blog/model-rights-are-data.html) (AI model rights from contract to host; publish checks on main, signed registry spec 026 record, host trust roots; runtime enforcement #1598 and prod signing #1567 still open). Also: [Signed model. Exact pin. Bit-identical hosts.](https://traverse-framework.com/blog/signed-exact-ref-digits.html) (v0.14.0 weekly demo; Browser+Node; test-only key). Also: [Domain packs are in scope: print-support](https://traverse-framework.com/blog/print-support-domain-pack.html) (capability pack; none published yet). Also: [v0.14.0: what changed for embedders](https://traverse-framework.com/blog/traverse-0-14-0-what-changed-for-embedders.html) (signed Spec 138; published exact-ref is native+web+Swift ExactModelHost on `swift-host-v0.14.0-4`; Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0, #1651; test-only digits-mlp key). Also: [Where business logic lives (hosts stay thin)](https://traverse-framework.com/blog/where-business-logic-lives.html). Weekly demo: [Same WASM. Browser and Node match. Agent still can’t freestyle.](https://traverse-framework.com/blog/same-wasm-multi-host.html) (v0.13.0 multi-host). Prior: [agent freestyle → blocked](https://traverse-framework.com/blog/agent-freestyle-blocked.html). Authoring: [You don't need Rust to publish a capability](https://traverse-framework.com/blog/you-dont-need-rust-to-publish-a-capability.html).
- [Discover](https://traverse-framework.com/discover.html): a live browser demo that pulls the public registry and executes a reviewed plan locally. Read [what it proves](https://traverse-framework.com/blog/what-discover-proves.html) before quoting it.
- [Compare: vs microservices](https://traverse-framework.com/compare/vs-microservices.html), [vs serverless](https://traverse-framework.com/compare/vs-serverless.html), [vs function calling](https://traverse-framework.com/compare/vs-function-calling.html), [vs agent runtimes](https://traverse-framework.com/compare/vs-agent-runtimes.html), [vs WASM runtimes](https://traverse-framework.com/compare/vs-wasm-runtimes.html), [vs cross-platform frameworks](https://traverse-framework.com/compare/vs-cross-platform-frameworks.html)
- [About](https://traverse-framework.com/about.html): project history and motivation.
Expand Down
2 changes: 1 addition & 1 deletion src/pages/blog/index.astro
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ const posts = [
{ href: '/blog/model-rights-are-data.html', title: 'Model rights are data, not a README', desc: 'Featured · Oct 6 · AI model rights from contract to host: offline publish checks, signed registry rights record, host trust roots, and what is still open.' },
{ href: '/blog/signed-exact-ref-digits.html', title: 'Signed model. Exact pin. Bit-identical hosts.', desc: 'Featured · Weekly demo: signed digits-mlp-1.0.0 exact-ref package, same bytes on Browser + Node via ExactModelBrowserHost; tamper fail-closed (digest_mismatch). Traverse v0.14.0. Test-only key.' },
{ href: '/blog/print-support-domain-pack.html', title: 'Domain packs are in scope: print-support without an app rewrite', desc: 'Featured · Manufacturing-shaped capability pack under discover→execute→trace; apps-not-ready ≠ no domain packs; hosts stay thin; none of the print.* capabilities published yet. registry#596 · #597–#604 · Discussion #1540.' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Native + web + Swift ExactModelHost execute; Kotlin/.NET do not execute exact-ref yet. crates/npm 0.14.0; that release pins registry 0.25.0.' },
{ href: '/blog/traverse-0-14-0-what-changed-for-embedders.html', title: 'v0.14.0: what changed for embedders', desc: 'Featured · Signed Spec 138 (schema 2.0.0 + model.sig.json), host-owned trust, registerPackage, digits-mlp-1.0.0 (test-only key). Published exact-ref: native + web + Swift ExactModelHost (swift-host-v0.14.0-4). Kotlin and .NET ExactModelHost are on main, not in Maven/NuGet 0.14.0 (#1651). crates/npm 0.14.0; that release pins registry 0.25.0.' },
{ href: '/blog/same-wasm-multi-host.html', title: 'Same WASM. Browser and Node match. Agent still can’t freestyle.', desc: 'Featured · Weekly demo: identical core.authorize@1.2.0 bytes on Browser + Node deny junior_analyst $2.4M wire; allow treasury_ops + MFA/dual-control. Traverse v0.13.0 multi-host.' },
{ href: '/blog/where-business-logic-lives.html', title: 'Where business logic lives (hosts stay thin)', desc: 'Featured · Narrative companion to the where-logic Q&A: capabilities hold non-UI domain rules; hosts = UI + I/O; utilities ≠ ceiling; apps-not-ready ≠ leave logic in the host.' },
{ href: '/blog/what-is-real-today-start-here.html', title: 'Start here: what is real in Traverse today', desc: 'Featured · Narrative companion to /what-is-real-today: discover→execute→trace, skill-first authoring, one shared runtime.wasm, honest consumers, pre-1.0.' },
Expand Down
2 changes: 1 addition & 1 deletion src/pages/blog/model-rights-are-data.astro
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ const _body = `

<h2 id="host">4. Host: trust roots belong to the host</h2>

<p>Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 <code>model.sig.json</code>). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Exact-ref execute runs on native Rust, the web embedder and Swift today; Kotlin and .NET don't execute exact-ref yet. See <a href="/questions/how-do-hosts-trust-signed-models.html">How do hosts trust signed models?</a></p>
<p>Traverse v0.14.0 shipped signed model packages (schema 2.0.0 manifests plus a detached Ed25519 <code>model.sig.json</code>). The app pins the manifest digest and the expected rights; the host owns the trusted keys, and apps can't inject their own. A naked URL is never identity. Discover → execute → trace, on one shared <code>runtime.wasm</code>. Published exact-ref execute is native Rust, the web embedder, and Swift <code>ExactModelHost</code> (<code>swift-host-v0.14.0-4</code>). Kotlin and .NET <code>ExactModelHost</code> are on traverse main and are not in the published 0.14.0 packages. See <a href="/questions/how-do-hosts-trust-signed-models.html">How do hosts trust signed models?</a></p>

<h2 id="open">What's still open (as of October 6, 2026)</h2>

Expand Down
4 changes: 2 additions & 2 deletions src/pages/blog/signed-exact-ref-digits.astro
Original file line number Diff line number Diff line change
Expand Up @@ -81,7 +81,7 @@ const _body = `
<tbody>
<tr><td>Browser</td><td><code>ExactModelBrowserHost</code> from <code>traverse-embedder-web@0.14.0</code>. <code>registerPackage(manifestBytes, wasm, signatureBytes)</code>.</td></tr>
<tr><td>Node</td><td>The same npm host under Node. Not a native Rust CLI invoke.</td></tr>
<tr><td>Not in this proof</td><td>Swift, Kotlin, and .NET do <strong>not</strong> execute exact-ref on the published <code>v0.14.0</code> pins used here.</td></tr>
<tr><td>Not in this proof</td><td>This demo is Browser + Node only, on one shared <code>runtime.wasm</code>. Swift <code>ExactModelHost</code> is published separately on <code>swift-host-v0.14.0-4</code>. The published Kotlin and .NET <code>0.14.0</code> packages do not include exact-ref execute.</td></tr>
</tbody>
</table>
</div>
Expand All @@ -99,7 +99,7 @@ const _body = `
<li><strong>Path:</strong> <code>ExactModelBrowserHost</code> + <code>registerPackage</code> (not <code>insertVerified</code>). Host-owned trust roots only.</li>
<li><strong>Smoke:</strong> 0→0, 7→7, 4→4 on Node; Browser label 0 bit-identical to Node; tamper → <code>digest_mismatch</code>; empty trust → <code>key_untrusted</code>.</li>
<li><strong>Signing key:</strong> test-only fixture. Production signing is <a href="https://github.com/traverse-framework/traverse/issues/1567" target="_blank" rel="noopener">traverse#1567</a>. Do not trust this key in a real host.</li>
<li><strong>Not claimed:</strong> Hugging Face. Catalog <code>model.execute</code> (the catalog still has none). Swift / Kotlin / .NET exact-ref execute on published 0.14.0. A separate native CLI. A second runtime.</li>
<li><strong>Not claimed:</strong> Hugging Face. Catalog <code>model.execute</code> (the catalog still has none). Exact-ref execute from the published Kotlin or .NET <code>0.14.0</code> packages. A separate native CLI. A second runtime.</li>
<li><strong>Lead claim:</strong> one shared <code>runtime.wasm</code>. Hosts = UI + I/O. Discover → execute → trace.</li>
</ul>
</div>
Expand Down
Loading
Loading