Public errata register
Sealed records are never edited. When one of them is wrong, we attach a public, signed correction to it — and the correction ships inside the artifact.
Audit
Record what each named protocol observed.
Diagnose
Trace each production finding to evidence.
Verify
Re-run the protocol required by the remediation.
Look up a scan id
Enter the scan id printed on an audit result, report, or PDF banner. If a correction is recorded for that scan, its full entry appears below; the register is lookup-only by design — it answers about one scan id at a time and publishes no browsing index of anyone's scans.
How to verify an entry
- Every entry is bound to the sealed evidence bundle of the scan it corrects. Recompute that bundle's digest from the published bundle JSON using the canonicalization recipe published at /diagnostics-proof: SHA-256 over the canonical JSON form — object keys recursively sorted lexicographically, no whitespace, UTF-8 — with the
bundleSha256field itself removed. The digest must equal thebundle_sha256on the entry. - The entry's own signature is vendor-verifiable under the same seal-key discipline the bundles use: HMAC-SHA256 over the domain separator
gm-errata-annotation/v1followed by the entry's canonical payload — its identity fields (id,scan_id,bundle_id,bundle_sha256,category,reason,provenance,published_at) serialized with sorted keys and no whitespace. The storedkey_idandalgoname the key generation and algorithm a verifier needs; our lookup re-verifies every stored signature on read and reports the result as the entry'sverifiedflag. - For bundle digest checks you can run yourself right now, the public reference verifier is at /verify.
Entries are append-only. A correction, once published, cannot be quietly edited or removed — the sealed record and its correction stay on the register together.
What this register covers
This register lists every defect known to us. Defects found by our own pipeline and by external evaluators both appear here; reported defects are acknowledged and enter the register before or with the fix that closes them.
An audit we later retract as our error entitles the purchaser to a free replacement scan.
Related surfaces: the changelog records methodology changes release by release, and the sample report shows the corrected www.usa.gov artifact that replaced the retracted example.