Check this receipt without trusting this site

gh attestation verify run-record-M-002.tar.gz --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/attest-bundle.yml

Expected output includes Verification succeeded!

NORTHSET

Proof-of-Pass Receipt

Receipt ID M-002

ISSUE / WORKNo issue or pull request recorded

REHEARSAL — NOT EXTERNAL VALIDATION

RUN0.9s

01 / TECHNICAL RESULT

Technical result

1/1

declared command passed

1/1 declared command returned exit 0 in the recorded environment

Upstream
PREPAREDmutable external state
Environment
node@sha256:2cf067cfed83d5ea958367df9f966191a942351a2df77d6f0193e162b5febfc0network phaseA:bridge,phaseB:none
Signature
verified Northset signing workflow provenance

02 / DECLARED CHECKS

Command evidence

Execution summary
1/1 declared command returned exit 0 in the recorded environment

  1. node bin/validate-mission.mjs examples/M-001_own_repo_rehearsal.json examples/M-004_verification_give.json examples/M-005_worker_mission.json

    exit 0 · 0.2s

unclassified executor time (derived residual) 0.6s

run wall (derived from recorded timestamps) 0.9s

Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.

03 / RECORDED IDENTITIES

Compact hashes

Container image digest
node@sha256:2cf067…5febfc0
Bundle contents digest
sha256:8913a8…beeb197
Signed asset SHA-256
sha256:74d666…bf78ebb

04 / CLAIMS BOUNDARY

NOT INCLUDED

  • Does not prove code quality
  • Does not prove security
  • Self-funded rehearsal on Northset's own repository; not external validation.
05 / Evidence annexTechnical · provenance · full recorded values
01

Technical evidence

Code, full environment, patch, and redacted outputs

Project

northset-oss/verification-pilot

Work

No issue or pull request recorded

Verification execution

runtime: northset-oss executor v0
human operator: aeziz

Code

base
af4fc4d4342dc40128828ebf95e3e49dad3934fa

Environment

image reference
node@sha256:2cf067cfed83d5ea958367df9f966191a942351a2df77d6f0193e162b5febfc0
repository digest
node@sha256:2cf067…5febfc0
network
phaseA:bridge,phaseB:none
Redacted stdout
=== cmd 1: node bin/validate-mission.mjs examples/M-001_own_repo_rehearsal.json examples/M-004_verification_give.json examples/M-005_worker_mission.json ===
Redacted stderr
=== cmd 1: node bin/validate-mission.mjs examples/M-001_own_repo_rehearsal.json examples/M-004_verification_give.json examples/M-005_worker_mission.json ===
02

Provenance & record

Full hashes, bundle identity, attestation, and record details

Record details

payment
none · not merge-contingent
redactions
none recorded
Bundle contents digest
sha256:8913a8…beeb197
Signed asset SHA-256
sha256:74d666…bf78ebb
Signed provenance recorded
verified

Full cryptographic values

Full recorded values. The compact receipt above shortens these for legibility only.

Container image digest
node@sha256:2cf067cfed83d5ea958367df9f966191a942351a2df77d6f0193e162b5febfc0
Bundle contents digest
sha256:8913a843c76dc93dffd0d1ed5fdd23b12cd5970a032c624513faaab7cbeeb197
Signed asset SHA-256
sha256:74d6669758500e108bf08b86970292d26ec291259313c9d4ec48df8fcbf78ebb

Signed bundle

Download signed bundle

Verify this receipt

gh attestation verify run-record-M-002.tar.gz --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/attest-bundle.yml

Attestation confirms that Northset's signing workflow produced this exact bundle. The signer does not witness the recorded run, and verification does not turn it into maintainer verification.

QR → receipt page
Self-funded rehearsal. Not external validation.

Evidence of what ran — not a verdict that the code is good.

SELF-FUNDED FIELD-TESTING.

All Northset work in northset-oss/verification-pilot →

FOR MAINTAINERS

Maintain northset-oss/verification-pilot?

Get this same run for any PR in your queue — private, free during the pilot, nothing published without your approval.

The issue form is public. Do not include secrets or private repository details there; use email instead.

Already onboarded? Add northset-verify to a PR to request a run on that PR.

Claims boundary

This page reports scoped proof-of-pass receipt evidence. It does not prove code quality, security, full CI coverage, production readiness, or maintainer approval. An attestation confirms bundle provenance; it does not broaden the receipt's claim.

Read the full Claims Boundary policy.