How It Works
The reposell listing operates as a serverless discovery layer over Git repositories.
Architecture
The listing is built on three pillars:
- Git-native registry — Products are published through pull requests containing JSON references to their
/sellendpoints - CI verification — Every PR is automatically verified against the seller's live endpoint before merge
- Static catalog — The product catalog is a static JSON index generated from verified listings
Verification Pipeline
When a pull request is submitted to the listing registry:
- The CI pipeline fetches the seller's
/sellendpoint - It validates the manifest, payment link, and health endpoint
- It verifies Ed25519 signatures on all signed data
- On pass, the PR is auto-merged; on fail, it's blocked with a reason
Trust Model
- Signatures are mandatory — Every listing must include a valid Ed25519 signature
- Fail-closed verification — Any verification failure blocks the listing
- Transparent pricing — Fee splits are signed by the policy and publicly verifiable
- No central authority — The protocol enforces trust, not a platform operator