Content authenticity is moving from detection to provenance
A seven-month GitHub cohort and package-usage snapshot test whether provenance, credentials, and identity binding are becoming an infrastructure category.
Provenance is established; identity binding remains early
51 subject-filtered implementations and packages show that provenance is already a visible implementation layer: signing and provenance appear in 96.1% of the cohort and reusable verification interfaces in 41.2%. Identity binding appears in only 0% and post-hoc detection in 3.9%. The data support a shift from detection toward provenance, but do not yet confirm the stronger claim that identity-bound workflows are becoming a mature category.
Market snapshot
Comparable measurements from independent market surfaces.
Implementations and packages
Deduplicated and subject-filtered primary cohort.
Median repository stars
Calculated across repositories with at least one star.
Registry packages
Real npm and PyPI package records, not synthetic entries.
Latest-month npm downloads
Usage surface only; downloads are not equivalent to customers.
Search-match dynamics
Bars show monthly GitHub Search API matches for provenance and content-credential terminology; loaded counts show the deduplicated repositories retained for detailed analysis.
What exists inside the category
One item may contain more than one feature.
Post-hoc AI detection
2 · 3.9%
Provenance and signing
49 · 96.1%
Identity binding
0 · 0%
Watermarking
6 · 11.8%
Verification SDKs and APIs
21 · 41.2%
Audit workflows
1 · 2%
Representative projects
Cross-source validation
These publications are not part of the primary numeric cohort.