NORTHSET
Proof-of-Pass Receipt
Receipt ID M-1009
ISSUE / WORKIssue #399 · PR #443
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUN1.2s
01 / TECHNICAL RESULT
Technical result
declared command passed
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
- Upstream
- OPENmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
OPENSSL_CONF=/dev/null PATH=/Users/aeziz-local/.nvm/versions/node/v22.22.3/bin:$PATH node --test test/list-packs-scroll-anchoring.test.mjsexit 0 · 0.4s
Checks not run
Focused regression test passed after the CSS fix.— not executed by the clean verifierThe regression test failed on the clean CSS with the declared output marker before the fix.— not executed by the clean verifierStylelint could not run because this managed environment returned `operation not permitted: npx`.— not executed by the clean verifier
run wall (derived from recorded timestamps) 1.2s
Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:d3a2f0…8216eba- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
0b9808039ed90278c2d1d56b083c7ded25fd3c8d- recorded patch commit
a1b247b297882dcdc9e54c04d12be6706d616c08
bound to verified tested tree- verified tested tree
c8225b40748eae9a08cf65d41d1bce7ef75e6227- patch diff SHA-256
sha256:d3a2f0…8216eba
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:33bc7a…de274dd- Publication observation
- inspect source publication status
- Factory PR state
- OPEN
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:d3a2f03b9f325f6d2f312d2cffb87400e07c65b9a0e1d848bf428c75a8216eba- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1009-a1b247b297882dcdc9e54c04d12be6706d616c08-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1009/a1b247b297882dcdc9e54c04d12be6706d616c08/proof.json'
gh attestation verify M-1009-a1b247b297882dcdc9e54c04d12be6706d616c08-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page