{
  "$comment": "Binding manifest for the public Hawser sample download. Regenerate with tools/make-verify-json.sh whenever FocusTimer.dmg changes.",
  "schema": 1,
  "product": "Hawser",
  "site": "https://hawserkit.com",
  "generated": "2026-09-07",
  "artifact": {
    "name": "FocusTimer.dmg",
    "url": "https://hawserkit.com/FocusTimer.dmg",
    "bytes": 1470864,
    "sha256": "723c5d702ae9a3fa6d33c50410df80c73ed9111064ccb6a4544bc7dc7306eb5f"
  },
  "expect": {
    "team_id": "46XWF4G66F",
    "authority": "Developer ID Application: ONUR YAVUZ (46XWF4G66F)",
    "dmg_notarization": "stapled",
    "app_bundle": "FocusTimer.app",
    "architectures": ["x86_64","arm64"],
    "minimum_macos": "13.0",
    "sparkle_version": "2.9.4"
  },
  "scope": {
    "proves": [
      "the exact bytes you downloaded match the bytes we published",
      "the outer DMG is Developer ID signed, notarised and stapled, and Gatekeeper accepts it",
      "the inner app passes codesign --verify --deep --strict and its Designated Requirement",
      "the app is a genuine universal binary with a 13.0 deployment target",
      "the bundled Sparkle updater and its XPC services are correctly signed and sandbox-ready"
    ],
    "does_not_prove": [
      "a live signed Sparkle update round trip -- the sample points at https://hawserkit.com/focustimer-appcast.xml, which answers and carries one EdDSA-signed item for this same 0.1.1, so Sparkle finds a valid signed feed and correctly reports there is nothing newer",
      "licence activation, offline grace, refund or revocation behaviour -- the sample ships POLAR_ORGANIZATION_ID=REPLACE_ME as a placeholder",
      "anything about the app's runtime behaviour; this manifest covers packaging, signing and distribution only"
    ]
  }
}
