A source-bearing, component-ID-addressed bundle input.
A component has one stable id, non-empty UTF-8 PTC-Lisp source, a sorted
duplicate-free list of component-ID dependencies, and a bounded origin
used for provenance and diagnostics. IDs match
[a-z][a-z0-9._-]{0,127}.
Components describe code and dependency identity only. They do not select providers or grant runtime authority.