A consumer control plane can validate and ingest the bundle by:
- Loading
integration-manifest.json. - Checking contract name and supported version.
- Verifying all output checksums.
- Validating finding records against the schema.
- Checking required fields, duplicate IDs, record counts and lineage edges.
- Rejecting local paths, secrets, private keys, JWTs and personal email addresses.
The local example is in examples/integration-consumer/.