Witness 0.4.0 is about depth. Reading a C2PA manifest tells you what a file claims. Checking it tells you whether the claim still belongs to the file. The same goes for the checks: a single-page app that renders its chat and images in the browser has an empty HTML shell, so a static scan finds nothing. Witness Pro 0.4.0 closes both gaps and lets you start the AI register from the spreadsheet you already have. @sweberdev/witness and @sweberdev/witness-react 0.4.0 are on npm under the MIT licence.
What is in 0.4.0
- Free:
readC2paManifests(bytes)returns the raw structure of a C2PA manifest store: the decoded claim, the signed claim bytes, every assertion with the bytes that are hashed, and the signature. It is the input for validators, and the Pro scanner builds on it. - Pro: C2PA verification in
witness-scan. For every image, sound or video with a manifest it checks the claim signature, the assertion hashes, the hash of the file content and the signer's certificate chain against trust anchors you supply, such as the C2PA trust list. A file that was changed after signing, an altered assertion or a broken signature is the newc2pa-invaliderror. With a trust list, an intact manifest from an unknown signer is thec2pa-untrustedwarning. - Pro: single-page apps. With
render, the scanner serves your build, opens the routes you list in headless Chromium and runs the same rules on the rendered page, so the chat notice and the AI images an app renders in the browser are checked. - Pro: register import.
witness-report import systems.csvreads a spreadsheet export into the register, with comma, semicolon or tab delimiters and English or German column headings, merges by id and names the line of any unusable row.witness-report exportwrites the register back. The report's check table shows how many files verified.
Verification tells you a manifest is intact and which certificate signed it. It does not tell you that what the manifest says is true. For MP4, MOV and M4A files the scanner checks signature and assertions, not yet the file binding.
Install
npm install @sweberdev/witness@0.4.0
import { readC2paManifests } from "@sweberdev/witness";
const manifests = readC2paManifests(bytes); // claim, assertions and signature per manifest
The images guide covers C2PA. In the live demo the scanner output now includes a file whose manifest no longer matches it.
Witness Pro 0.4.0
The three Pro packages move to 0.4.0 together. Add the trust list and the render routes to the scan section of witness.config.json:
{
"scan": {
"root": "dist",
"c2pa": { "trustAnchors": ["trust/c2pa-trust-list.pem"] },
"render": { "routes": ["/", "/support"], "waitFor": "#chat" }
}
}
Rendering needs the optional playwright-core and a Chromium. See the scanner docs and the report docs, and the Witness page for the Pro edition.