Skip to content
ECZ-IDSDK

Workflow bundle · ECZ-ID SDK

ECZ-ID Extension Publisher Assurance Bundle

Give buyers a consistent publisher and release story across distribution ecosystems.

A bundle for publishers shipping add-ons and the packages behind them into more than one registry or distribution channel.

Type
Bundle
Price
Not restated on this site; TrustOps publishes the current price and availability
Acquired and paid in
TrustOps
Operated in · proved by
Dashboard · Resolver

The problem

Why it matters.

A publisher shipping add-ons and the packages they depend on faces the same publisher and release questions in every ecosystem, answered differently each time.

Built for

  • Publishers of add-ons and the packages behind them
  • Developer-tools vendors
  • Teams shipping to more than one registry or distribution channel

What changes

  • Consistent publisher evidence
  • Clearer permission review
  • Reusable release artefacts

What you receive

Concrete deliverables, not a vague trust score.

  • The ECZ-ID SDK Release Provenance & Customer Assurance Kit and its companion assurance components
  • Registry, distribution-channel and release context
  • Publisher review artefacts
A publisher assurance view
Publisher
One organisation across every ecosystem
Products
Each SDK or library's own ECZ-ID, with the places it appears recorded as bindings
Packages
The packages and libraries behind them
Releases
Release context and evidence, where supplied
Boundary
Supports review — does not guarantee acceptance by any registry or distribution channel

Illustrative structure.

How it works

A short path from need to something usable.

  1. Identify the products you publish together.

  2. Map the registries, distribution channels and packages they reach.

  3. Complete the evidence.

  4. Package the publisher view.

How it relates to your Passport

Each SDK or library and each package keeps its own free Passport. The bundle connects them under one publisher story without merging identities.

Use cases

  • An SDK publisher whose SDK also ships as editor extensions and a GitHub Action.
  • A developer-tools company whose plugins ship alongside the SDKs they are built on.

Tiers and price

Price and availability

Prices and what can be bought today come from TrustOps, which owns every purchase, entitlement and renewal. This site does not restate this product's price; TrustOps publishes its current tiers, price and availability, and shows them before anything is bought.

How it is arranged

  1. TrustOps acquires

    TrustOps publishes the tiers and holds payment and entitlement whenever it is offered.

  2. Dashboard operates

    Once you hold it, it appears in your Dashboard, where you operate it.

  3. Resolver proves

    Public facts stay on the Resolver; holding it never changes what a record proves.

Privacy, security and evidence

What is collected, published and kept.

  • Bundling evidence does not merge the underlying identities.
  • Publication of each record stays your decision.

Boundaries

The claims stop here.

  • The bundle supports review; it does not guarantee acceptance by any registry or distribution channel.

Integrations and questions

Works with what you already run.

  • Plugin and SDK Passports, each kept distinct.
  • The ECZ-ID SDK Release Provenance & Customer Assurance Kit, for the packages behind the extensions.
Why is this relevant to an SDK publisher?
Extensions and plugins are built on SDKs and published as packages. The bundle gives the publisher one story across both, with each identity kept distinct.