Check this receipt without trusting this site

Factory proof attestation for the exact immutable proof bytes.

curl --fail --silent --show-error --location --output M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1001/370bc991d0d42c746b2f0e3240dbdc529813adf0/proof.json'
gh attestation verify M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.yml

Expected output includes Verification succeeded!

NORTHSET

Receipt Evidence Record

Receipt ID M-1001

ISSUE / WORKIssue #3364 · PR #4222

CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION

RUNnot recorded in the immutable source proof

01 / TECHNICAL RESULT

Technical result

structured command evidence unavailable

The legacy proof records a patched observation with exit code 0 but does not identify the executed command or its timing; no public PASS is derived.

Upstream
OPENmutable external state
Environment
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
Signature
proof attestedGitHub artifact attestation for the exact proof bytes

02 / DECLARED CHECKS

Command evidence

Execution summary
The legacy proof records a patched observation with exit code 0 but does not identify the executed command or its timing; no public PASS is derived.

No structured executed command was recorded.

Legacy declarations

Preserved verbatim from the immutable proof; not interpreted as executed command evidence.

  • PASS: Play on TV rule contains remote and AirPlay selectors
  • BLOCKED: npm test -- --runInBand tests/unit/player-remote-button.test.js — zsh:1: operation not permitted: npm

No command-level PASS is claimed. The immutable legacy proof did not record a structured executed command or verification timestamps.

03 / RECORDED IDENTITIES

Compact hashes

Patch diff SHA-256
sha256:f052ba…176c207
Container image digest
sha256:53ac35…5342f5d

04 / CLAIMS BOUNDARY

NOT INCLUDED

  • Legacy factory proof: structured executed commands and verification timestamps were not recorded.
  • The original free-form checks are preserved as legacy declarations and are not interpreted as executed command evidence.
  • Contributor self-run; not maintainer verification.
  • Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01

Technical evidence

Code, full environment, patch, and redacted outputs

Project

code-charity/youtube

Work

Issue #3364 · PR #4222

Verification execution

runtime: Northset factory (node)
human operator: Northset mission operator

Code

base
077a84b001ca59c1ea69a51db0bfb65af2e9ba91
recorded patch commit
370bc991d0d42c746b2f0e3240dbdc529813adf0
bound to verified tested tree
verified tested tree
325a1ba04ca82829b233fcbacd333f8f00475650
patch diff SHA-256
sha256:f052ba…176c207
bound to executed patch bytes

Environment

image reference
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
repository digest
sha256:53ac35…5342f5d
network
none
02

Provenance & record

Full hashes, bundle identity, attestation, and record details

Record details

payment
none recorded · not merge-contingent
redactions
none recorded
Bundle contents digest
not recorded; raw proof identity is listed below
Immutable raw proof
inspect source proof
Raw proof SHA-256
sha256:b540c9…ed9aca7
Publication observation
inspect source publication status
Factory PR state
OPEN
Factory attestation state
RECEIPT_ATTESTED
Factory status observed
Factory proof attestation
recorded for the exact proof bytes

Full cryptographic values

Full recorded values. The compact receipt above shortens these for legibility only.

Patch diff SHA-256
sha256:f052ba4d84809fde46c163e4f8dff9dd246b4e1443d1826bf4357abf7176c207
Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d

Factory proof attestation

Open factory proof attestation

Verify the factory proof

curl --fail --silent --show-error --location --output M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1001/370bc991d0d42c746b2f0e3240dbdc529813adf0/proof.json'
gh attestation verify M-1001-370bc991d0d42c746b2f0e3240dbdc529813adf0-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.yml

This attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.

QR → receipt page
Contributor self-run from immutable factory proof; not maintainer verification.

Legacy evidence is incomplete — no command-level PASS is claimed.

SELF-FUNDED FIELD-TESTING.

- - - detach here - - -

External status

Mutable upstream observation; unattested and separate from the signed run record.

PR state
OPEN
GitHub review decision
NONE
Upstream updated
Observed
OPEN

Factory publication observation · open linked record

All Northset work in code-charity/youtube →

FOR MAINTAINERS

Maintain code-charity/youtube?

Get this same run for any PR in your queue — private, free during the pilot, nothing published without your approval.

The issue form is public. Do not include secrets or private repository details there; use email instead.

Already onboarded? Add northset-verify to a PR to request a run on that PR.

Claims boundary

This page preserves incomplete legacy factory evidence and does not claim a command-level PASS. It does not prove code quality, security, full CI coverage, production readiness, or maintainer approval. The factory proof attestation is bound to the exact proof bytes. It does not attest a legacy signed bundle or broaden the receipt's claim.

Read the full Claims Boundary policy.