NORTHSET
Proof-of-Pass Receipt
Receipt ID M-1011
ISSUE / WORKIssue #381 · PR #417
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUN6.7s
01 / TECHNICAL RESULT
Technical result
declared command passed
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
- Upstream
- MERGEDmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
node --import tsx --test src/hotkeys/__tests__/hotkeyStore.test.tsexit 0 · 3.2s
run wall (derived from recorded timestamps) 6.7s
Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:f70736…d5432c6- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- No manual macOS UI verification was performed.
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
Open-Resin-Alliance/DragonFruit
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
1fdc757fc90748dfc609eb4d460e47b3fecf8236- recorded patch commit
03572c4a4cc73eaf233827d5b1fb6d372c572d79
bound to verified tested tree- verified tested tree
a6110186aba44e68022c207d4cc1a30fa05a6b9d- patch diff SHA-256
sha256:f70736…d5432c6
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:0e4172…906a968- Publication observation
- inspect source publication status
- Factory PR state
- MERGED
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:f707360bd1298bcc6a6e87c1b8493cff97107b865f473d3ea73af06d5d5432c6- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1011-03572c4a4cc73eaf233827d5b1fb6d372c572d79-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1011/03572c4a4cc73eaf233827d5b1fb6d372c572d79/proof.json'
gh attestation verify M-1011-03572c4a4cc73eaf233827d5b1fb6d372c572d79-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page