{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "manni:citations-strict:1.0.0",
  "title": "manni citations strict overlay v1.0.0",
  "description": "The strict overlay for manni:citations:1.0.0. Stack it beside the open vocabulary, which owns every key and every required rule. It asks for the full commit hash a tool writes, and it pairs the pin's prefix with the source file.",
  "additionalProperties": true,
  "type": "object",
  "properties": {
    "citations": {
      "description": "Strict narrows each entry's `source`. An encrypted `file` takes an `hmac-sha256-` pin, a plain one takes a `sha256-` pin, and `commit-sha` is a full hash.",
      "items": {
        "properties": {
          "source": {
            "properties": {
              "commit-sha": {
                "pattern": "^(?:[0-9a-f]{40}|[0-9a-f]{64})$",
                "description": "A full commit hash, forty lowercase hex digits or sixty-four in a SHA-256 repository."
              }
            },
            "if": {
              "properties": {
                "file": {
                  "pattern": "^~"
                }
              },
              "required": [
                "file"
              ]
            },
            "then": {
              "properties": {
                "integrity": {
                  "pattern": "^hmac-sha256-",
                  "description": "An encrypted `file` is pinned `hmac-sha256-`."
                }
              }
            },
            "else": {
              "properties": {
                "integrity": {
                  "pattern": "^sha256-",
                  "description": "A plain `file` is pinned `sha256-`."
                }
              }
            }
          }
        }
      }
    }
  }
}
