App catalog
Self-hostable OSS packages SIAX can plan, install and run — with the qualification channels kept apart: candidate (a real candidate, not proven installable), tested (proven installable: recorded digest + passing license gate) and managed_qualified (SIAX runs it under an SLA, certified by a protected verifier). 0 entries are visibly capped down after lost upstream evidence — never silently re-qualified. The same data as JSON: /v1/api0/app-catalog.