NORTHSET
Receipt Evidence Record
Receipt ID M-1001
ISSUE / WORKIssue #3364 · PR #4222
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUNnot recorded in the immutable source proof
01 / TECHNICAL RESULT
Technical result
structured command evidence unavailable
The legacy proof records a patched observation with exit code 0 but does not identify the executed command or its timing; no public PASS is derived.
- Upstream
- OPENmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
The legacy proof records a patched observation with exit code 0 but does not identify the executed command or its timing; no public PASS is derived.
No structured executed command was recorded.
Legacy declarations
Preserved verbatim from the immutable proof; not interpreted as executed command evidence.
PASS: Play on TV rule contains remote and AirPlay selectorsBLOCKED: npm test -- --runInBand tests/unit/player-remote-button.test.js — zsh:1: operation not permitted: npm
No command-level PASS is claimed. The immutable legacy proof did not record a structured executed command or verification timestamps.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:f052ba…176c207- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- Legacy factory proof: structured executed commands and verification timestamps were not recorded.
- The original free-form checks are preserved as legacy declarations and are not interpreted as executed command evidence.
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
077a84b001ca59c1ea69a51db0bfb65af2e9ba91- recorded patch commit
370bc991d0d42c746b2f0e3240dbdc529813adf0
bound to verified tested tree- verified tested tree
325a1ba04ca82829b233fcbacd333f8f00475650- patch diff SHA-256
sha256:f052ba…176c207
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:b540c9…ed9aca7- Publication observation
- inspect source publication status
- Factory PR state
- OPEN
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:f052ba4d84809fde46c163e4f8dff9dd246b4e1443d1826bf4357abf7176c207- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1001/370bc991d0d42c746b2f0e3240dbdc529813adf0/proof.json'
gh attestation verify M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page