Verify the registry envelope, every per-package capsule signature, and each
artifact's content digest — entirely in your browser. The only trust root is
registry.pub (the UMS publisher Ed25519 key). Load it from this origin,
or paste a saved copy for a fully air-gapped check.
registry.json + registry.json.sig + registry.pub to verify with zero network.—
.well-known/ums-integrity.json from its own origin and confirm its artifactDigest matches the signed capsule. The signature + digest themselves are already verified offline above.—