> Canonical guide: https://developers.foxlight.ai/build/catalogs/
> Contract snapshots: Skulk 2.0.0 (b0af39c79b6b7102b2478062904f1d7cc8619975); SDK 0.4.0 (31bb090b8f64689f87514e48385e22b6ad94a6c2). Check the installed runtime when versions differ.

# Signed catalogs and release sources

A signed catalog identifies immutable plugin release bytes and their compatibility. Installation verifies trusted metadata and artifacts before staging or activation.

## How it works

Publishing a descriptor is separate from publishing an installable package. An operator reviews requested permissions, setup requirements and trust before installation. Revoked, expired, or mismatched artifacts do not gain authority from discovery.

## Complete contract

Read the [Skulk 2.0 development guide](https://docs.foxlight.ai/skulk/next/extensions/#owner-configured-private-release-source) for the complete parameters, constraints, examples and operational behavior.
