Packet identity

Packet ID
events:series-nist-software-supply-chain-assurance-forum
Packet SHA-256 identity
a5476749969302bdd54fbcc463f15e5d37507851da3396a68d31754462ac4d1b
Corpus SHA-256 identity
8fa944604ca189f5a9216ca59f640ad2ca20972ad512f2f4970764716782e18d
Release ID
public-alpha-2026-07-26-research-visuals-r14
Source commit
3eb036fce3d711336c8c605625895e8a2e799ab0
Frozen corpus date
2026-07-25
Primary records
2
Reference sources
1

Questions and exclusions

Required questions

  1. Required question 1 (exact ID: question-1)
    Do the official sources support the series identity and every current occurrence, date, deadline, access rule, and eligibility statement?
  2. Required question 2 (exact ID: question-2)
    Are location, remote access, accommodations, cost, travel, visa, and participation uncertainty represented without invention?
  3. Required question 3 (exact ID: question-3)
    Does the founder action remain proposed and separately authorized rather than implied as registration or attendance?

Explicit exclusions

  • A listed event is not endorsed, sponsored, attended, booked, or affiliated with GShips.
  • A current occurrence can expire; historical packet approval cannot establish a future event date.

Requested controlled scopes: accessibility-disability-justice, event-access-freshness

Frozen-evidence decision window: 14 days from the packet freeze. A current-occurrence approval must be decided no later than the frozen occurrence end date; a later review requires a refreshed record and packet.

Complete primary record set

Every record below has one primary packet owner. Decisions must bind to the exact record and packet fingerprints; a changed lesson body, evidence grade, citation, locator, source snapshot, requirement, policy, release, or commit expires the old packet.

  1. event-series · series-nist-software-supply-chain-assurance-forum

    NIST Software and Supply Chain Assurance Forum

    Record fingerprint
    765db3d9a075b9e5f8d2ae641084bd47308a4e160dec787e816c85639eaa1fcd
    Minimum approvals
    1
    Required scope groups
    bounded-competence: event-access-freshness
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    series-nist-software-supply-chain-assurance-forum
    Slug
    nist-software-supply-chain-assurance-forum
    Name
    NIST Software and Supply Chain Assurance Forum
    Occurrence IDs
    1. event-nist-software-and-supply-chain-assurance-forum
    Organizer Organization IDs
    None recorded
    Relationship
    indexed only; no formal relationship
  2. event-occurrence · event-nist-software-and-supply-chain-assurance-forum

    NIST Software and Supply Chain Assurance Forum

    Record fingerprint
    abeee8bf7a0996bd2f242a4c15ccfc9faa810c25c3e0fc5140179d8a5ffaac96
    Minimum approvals
    1
    Required scope groups
    bounded-competence: accessibility-disability-justice, event-access-freshness
    High-consequence domains
    None under the named two-person rule
    Review state
    pending
    Published human decisions
    0
    Inspect the complete frozen review surface
    ID
    event-nist-software-and-supply-chain-assurance-forum
    Slug
    nist-software-and-supply-chain-assurance-forum
    Name
    NIST Software and Supply Chain Assurance Forum
    Start Date
    2026-09-22
    End Date
    2026-09-23
    Location
    McLean, United States
    Focus
    Software supply chain, SBOMs, provenance, and assurance
    Founder Action
    Evaluate attendance as a public software-assurance learning option; register only after schedule, travel, accessibility, and a specific Update Airlock learning agenda are approved.
    Access Notes
    NIST lists the September 22–23 forum as in person at MITRE in McLean, free and open to the public, with registration required and now open. NIST says tentative topics will be available in late July and a draft agenda in August. Capacity, accessibility, recording, host-site access, and final agenda fit require confirmation.
    Eligibility
    The forum is described as open to the public, subject to required registration and the host site's access procedures. No registration, attendance, or NIST/MITRE relationship has been undertaken.
    Action Status
    proposed; not undertaken
    Status
    monitor
    Verified At
    2026-07-26
    Conflicts
    Publisher intends to explore a commercial venture based on some GShips work; no event registration, submission, sponsorship, attendance commitment, or organizer relationship exists.
    Evidence Boundary
    NIST's SSCA series page supports the next occurrence's dates, location, free/public status, and registration requirement; it does not establish agenda quality, GShips fit, accessibility, capacity, admission, or participant availability.
    What Would Change
    A NIST update to the occurrence date, venue, agenda, registration availability, public-access rule, or host-site requirements would change this profile.
Equivalent record table for this packet
RecordSubjectFingerprintApprovalsScope groups
event-series:series-nist-software-supply-chain-assurance-forum NIST Software and Supply Chain Assurance Forum 765db3d9a075b9e5f8d2ae641084bd47308a4e160dec787e816c85639eaa1fcd 1 bounded-competence: event-access-freshness
event-occurrence:event-nist-software-and-supply-chain-assurance-forum NIST Software and Supply Chain Assurance Forum abeee8bf7a0996bd2f242a4c15ccfc9faa810c25c3e0fc5140179d8a5ffaac96 1 bounded-competence: accessibility-disability-justice, event-access-freshness

Linked records—not review targets here

These records provide dependency or relationship context. Their decisions belong to their single primary packet, preventing double counting.

Frozen source snapshots

Source inclusion does not determine the disposition. Reviewers must inspect the cited locator and relation, note inaccessible material, and identify stronger or conflicting evidence.

Sources, verification dates, scope notes, and exact fingerprints
Source IDSourceCheckedScope boundaryFingerprint
official-event-occurrence-event-nist-software-and-supply-chain-assurance-forum NIST Software and Supply Chain Assurance Forum (opens external site in a new tab) 2026-07-26 NIST's SSCA series page supports the next occurrence's dates, location, free/public status, and registration requirement; it does not establish agenda quality, GShips fit, accessibility, capacity, admission, or participant availability. c0d4ed94fa570b9ad7bebf62b2a5139e9c4112dc44529f08fa6f73a077975001

Offline packet and worksheet

Downloads contain no reviewer contact details. Downloading does not create an account or store a review response in the GShips application. Ordinary provider request or analytics logs may record the download request. Work locally: the public site has no review account, upload endpoint, or decision-submission API.

Frozen packet · JSON

15.4 KB · packet identity a5476749969302bd…

Download packet

Blank decision worksheet · JSON

3.7 KB · template identity fd9213d4228a223d…

Download blank JSON

Review-notes worksheet · Markdown

Readable notes companion only—not a decision-bundle equivalent. Use the closed JSON template for structural validation.

Download notes worksheet

Do not paste a completed decision, identity documents, private contact data, confidential conflict evidence, medical information, controlled material, or exploit details into a public form. Until a separately authorized private handoff exists, retain the completed worksheet locally.

Packet schema · JSON · Decision-bundle schema · JSON

Validate offline

Use Node.js 22.13.0 or later. Keep the packet, worksheet, completed decision, and all six kit files together in a local directory.

  1. Download the six kit files below. Complete a copy of the JSON template offline and preserve its templateFingerprint.
  2. Finalize a separate output file.
    node finalize-review-decision.mjs \
      --input DRAFT.json \
      --output COMPLETED.json

    This marks the copy complete and calculates an unkeyed canonical bundle fingerprint. A fingerprint detects changes; it is not a reviewer signature.

  3. Validate the packet and completed copy.
    node check-review-decisions.mjs \
      --packet PACKET.json \
      --decision COMPLETED.json

    Add another --decision for each independent reviewer.

  4. Interpret the result narrowly. A zero exit proves structural consistency only. Neither command appoints or qualifies a reviewer, establishes independence, accepts a decision, or authorizes publication.

Completion criteria

Every primary record must receive the required number of valid, current-fingerprint approvals; every complementary scope group and required domain must be covered; any unresolved revise, contest, or reject disposition blocks publication.

Named medical, reproductive, nuclear, radiation, cybersecurity, governance, and dual-use conclusions require two distinct qualified independent humans covering complementary domain-method and rights/public-interest scopes.

  • Reviewer identity, qualification, independence, conflicts, and compensation must be assessed by accountable human governance; local validation can only report structural validity.
  • Approve, revise, contest, reject, and recuse remain visible. A negative finding cannot be hidden by an aggregate approval percentage.
  • Revision creates a new record and packet fingerprint. Prior approvals do not carry forward automatically.
  • AI may assist with clerical comparison but cannot count as an independent reviewer, identity attestor, appeal authority, or second person.

Prepared review packet · 0 published human decisions · Independent review pending · Suggest a correction

Accountability record

How to inspect this page

Scope: Prepared review packet events:series-nist-software-supply-chain-assurance-forum · a5476749969302bdd54fbcc463f15e5d37507851da3396a68d31754462ac4d1b

Page citations and accountability links

  • Exact frozen packet
    Complete packet payload; SHA-256 a5476749969302bdd54fbcc463f15e5d37507851da3396a68d31754462ac4d1b · fingerprint-bound review artifact
  • Blank closed decision template
    Offline structured-decision starting point · unsubmitted local artifact
  • Review-notes worksheet
    Human-readable notes companion; not validator input · offline notes aid
  • Review corpus index
    Corpus SHA-256 8fa944604ca189f5a9216ca59f640ad2ca20972ad512f2f4970764716782e18d · release and ownership index

Assumptions and limits

  • The exact packet, record, source, policy, release, and source-commit fingerprints bound this prepared page; human review has not started.
  • Downloading, local structural validation, or completing notes does not appoint or qualify a reviewer, establish independence, accept a decision, authorize publication, or create a relationship.

What would change this page?

Staffed governance, appointed qualified reviewers, completed record-level decisions, published conflicts, minority findings, corrections, or changed review policy would change this page.

People, review, and conflicts

Prepared by
GShips Project
Editorial status
public-alpha accountability pass
Editorial reviewer
GShips Project AI-assisted editorial synthesis
Last editorial review
2026-07-26
Independent review
pending
Independent reviewer
No independent reviewer assigned
Last independent review
No independent-review date exists
Last content edit
2026-07-25

Declared conflicts

  • The maintainer intends to explore a commercial venture based on some GShips work. No entity, outside funding, customer, sponsor, or indexed-organization relationship currently exists.

Suggest a correction to this page