Skip to main content

Public errata register

Sealed records are never edited. When one of them is wrong, we attach a public, signed correction to it — and the correction ships inside the artifact.

Audit

Record what each named protocol observed.

Diagnose

Trace each production finding to evidence.

Verify

Re-run the protocol required by the remediation.

Look up a scan id

Enter the scan id printed on an audit result, report, or PDF banner. If a correction is recorded for that scan, its full entry appears below; the register is lookup-only by design — it answers about one scan id at a time and publishes no browsing index of anyone's scans.

How to verify an entry

  1. Every entry is bound to the sealed evidence bundle of the scan it corrects. Recompute that bundle's digest from the published bundle JSON using the canonicalization recipe published at /diagnostics-proof: SHA-256 over the canonical JSON form — object keys recursively sorted lexicographically, no whitespace, UTF-8 — with the bundleSha256 field itself removed. The digest must equal the bundle_sha256 on the entry.
  2. The entry's own signature is vendor-verifiable under the same seal-key discipline the bundles use: HMAC-SHA256 over the domain separator gm-errata-annotation/v1 followed by the entry's canonical payload — its identity fields (id, scan_id, bundle_id, bundle_sha256, category, reason, provenance, published_at) serialized with sorted keys and no whitespace. The stored key_id and algo name the key generation and algorithm a verifier needs; our lookup re-verifies every stored signature on read and reports the result as the entry's verified flag.
  3. For bundle digest checks you can run yourself right now, the public reference verifier is at /verify.

Entries are append-only. A correction, once published, cannot be quietly edited or removed — the sealed record and its correction stay on the register together.

What this register covers

This register lists every defect known to us. Defects found by our own pipeline and by external evaluators both appear here; reported defects are acknowledged and enter the register before or with the fix that closes them.

An audit we later retract as our error entitles the purchaser to a free replacement scan.

Related surfaces: the changelog records methodology changes release by release, and the sample report shows the corrected www.usa.gov artifact that replaced the retracted example.