Verify a model manifest's provenance, signer, digest status, and expiry before loading it into a service.
Required APIdef verify_model_manifest(manifest, approved_signers, required_fields, now):
return {'valid': ..., 'error': ...}BehaviorThink through the mechanism first if you want the extra reasoning step. It never blocks the editor.
verify_model_manifest({'digest': 'abc', 'source': 'hub', 'signer': 'team', 'signature_valid': True, 'expires': 10}, ['team'], ['digest', 'source'], 3)trusted provenance is a deployment prerequisite
verify_model_manifest({'digest': 'abc', 'source': 'hub', 'signer': 'team', 'signature_valid': False, 'expires': 10}, ['team'], ['digest', 'source'], 3)['error']a digest without verification is not trustworthy
2 hidden edge tests run after the visible contract passes.
Run Tests to see the contract verdicts here.