NORTHSET
Proof-of-Pass Receipt
Receipt ID M-1041
ISSUE / WORKIssue #492 · PR #899
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUN1.3s
01 / TECHNICAL RESULT
Technical result
declared command passed
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
- Upstream
- OPENmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
OPENSSL_CONF=/dev/null node --test __tests__/pages/About.content.test.mjsexit 0 · 0.4s
run wall (derived from recorded timestamps) 1.3s
Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:12085a…e7e4e64- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- Secret-backed data generators, full Jest, production build, and deploy preview were not run.
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
b851d5dbcc12f9eeed8d774588fef78939e6228c- recorded patch commit
0ef7c9dfcc830d6dd374d4a7181651d601c3504e
bound to verified tested tree- verified tested tree
5e8e1ebfdee1b178264b7a0bbf09845888c3ca8e- patch diff SHA-256
sha256:12085a…e7e4e64
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:52d444…c5bd44d- Publication observation
- inspect source publication status
- Factory PR state
- OPEN
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:12085a9ddc620f85a395ee92189691e95c493bd79f39a0eaa874e6f34e7e4e64- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1041-0ef7c9dfcc830d6dd374d4a7181651d601c3504e-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/4f890feab19cf025cefb6e3b7adbc6a49e1040f8/receipts/M-1041/0ef7c9dfcc830d6dd374d4a7181651d601c3504e/proof.json'
gh attestation verify M-1041-0ef7c9dfcc830d6dd374d4a7181651d601c3504e-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page