NORTHSET
Proof-of-Pass Receipt
Receipt ID M-1010
ISSUE / WORKIssue #150 · PR #319
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUN1.1s
01 / TECHNICAL RESULT
Technical result
declared command passed
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
- Upstream
- CLOSED UNMERGEDmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
OPENSSL_CONF=/dev/null node test/main-shortcut.test.jsexit 0 · 0.3s
Checks not run
Focused regression test passed: 1 test, 0 failures.— not executed by the clean verifierNode syntax checks passed for src/main.js and test/main-shortcut.test.js.— not executed by the clean verifiernpm test could not run because npm execution was denied by the workspace environment.— not executed by the clean verifier
run wall (derived from recorded timestamps) 1.1s
Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:599961…1b256f7- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
AprilSylph/Palettes-for-Tumblr
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
2a46512c7fbd58f1dd73993397e8cac6fb39d6d8- recorded patch commit
af652fd73ccb061d80bf82317b161d7c66957946
bound to verified tested tree- verified tested tree
dd84370fb8a38284bfc3cab93c06d2e5dbff6227- patch diff SHA-256
sha256:599961…1b256f7
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:c8b8b2…3d8cd3e- Publication observation
- inspect source publication status
- Factory PR state
- CLOSED
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:599961a0d8346b9e7194a0077a176bdf0acbf93e39cca12787ee96a731b256f7- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1010-af652fd73ccb061d80bf82317b161d7c66957946-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1010/af652fd73ccb061d80bf82317b161d7c66957946/proof.json'
gh attestation verify M-1010-af652fd73ccb061d80bf82317b161d7c66957946-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page