Analysis reads only the assembled release-input bundle — content-pinned store objects plus content-pinned repository artifacts. It never reads the live store or unmanifested working files.
orderingentries sorted by path, UTF-8 byte order
encodingUTF-8; object digests over raw bytes, unmodified
newline policynone applied to bodies; manifest has no trailing newline
excluded metadataHTTP headers, download timestamps, local filenames
numeric serializationjson separators=(',',':'), sort_keys=True
duplicate handlingunique paths enforced; a duplicate path is a hard error
32 INPUTS · MANIFEST 5bd8d96f6a8e15a6f6a8c9dc
Without a canonicalization contract, the same logical records can produce different aggregate hashes across implementations. Ordering strings are generated by a tie-aware formatter and are never hand-authored.