Observed arrival · 2026-09-10
ArtifactMark keeps release evidence tied to the exact bytes
ArtifactMark is a version-specific evidence system for checking what was assessed before installing a software artifact.
Field notes
ArtifactMark separates the identity of released bytes from the decision record describing their assessment. Its evidence model names an artifact digest, an assessment ID, and a coverage state for passed, failed, skipped, or unavailable checks. The homepage’s example compares an assessed release, 4f2a1c9, with 7d8e12b, where a new package.json postinstall script means the later version needs assessment. Maintainer participation is described as opt-in, with invitation-based accounts and processes for requests, disputes, and withdrawal.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue