NORTHSET
Proof-of-Pass Receipt
Receipt ID M-1047
ISSUE / WORKIssue #106 · PR #191
CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION
RUN2.7s
01 / TECHNICAL RESULT
Technical result
declared command passed
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
- Upstream
- CLOSED UNMERGEDmutable external state
- Environment
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5dnetwork none
- Signature
- proof attestedGitHub artifact attestation for the exact proof bytes
02 / DECLARED CHECKS
Command evidence
Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations
OPENSSL_CONF=/dev/null node --test test/animation.test.jsexit 0 · 0.6s
run wall (derived from recorded timestamps) 2.7s
Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.
03 / RECORDED IDENTITIES
Compact hashes
- Patch diff SHA-256
sha256:f55a2d…5b5b59f- Container image digest
sha256:53ac35…5342f5d
04 / CLAIMS BOUNDARY
NOT INCLUDED
- The rendered-app smoke exercised the server-side Express/Handlebars home route and verified its generated logo metadata, but did not run a graphical browser or assistive technology.
- The SVG check proves that all 24 referenced files exist; it does not visually inspect their rendered appearance.
- Contributor self-run; not maintainer verification.
- Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01Technical evidence
Code, full environment, patch, and redacted outputs
Technical evidence
Code, full environment, patch, and redacted outputsProject
jointhefediverse-net/jointhefediverse.net
Work
Verification execution
runtime: Northset factory (node)
human operator: Northset mission operator
Code
- base
70d3b1978b1dfb36511066d0cadc52a5f2dc5546- recorded patch commit
a3483808bb11802698c5f4ff1ea5e9eae0880408
bound to verified tested tree- verified tested tree
42861fbb49b1577d8e1f92092ce0632eef31b913- patch diff SHA-256
sha256:f55a2d…5b5b59f
bound to executed patch bytes
Environment
- image reference
- sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
- repository digest
sha256:53ac35…5342f5d- network
- none
02Provenance & record
Full hashes, bundle identity, attestation, and record details
Provenance & record
Full hashes, bundle identity, attestation, and record detailsRecord details
- payment
- none recorded · not merge-contingent
- redactions
- none recorded
- Bundle contents digest
- not recorded; raw proof identity is listed below
- Immutable raw proof
- inspect source proof
- Raw proof SHA-256
sha256:229ac0…884feaa- Publication observation
- inspect source publication status
- Factory PR state
- CLOSED
- Factory attestation state
- RECEIPT_ATTESTED
- Factory status observed
- Factory proof attestation
- recorded for the exact proof bytes
Full cryptographic values
Full recorded values. The compact receipt above shortens these for legibility only.
- Patch diff SHA-256
sha256:f55a2dd7ee7d7b9649ff8d060704b0c586e60501af45d7cb7488f45685b5b59f- Container image digest
sha256:53ac35edd320b9e6442195b6334e8ae2a9396167a7a92cbf6dd53cb475342f5d
Factory proof attestation
Open factory proof attestation
Verify the factory proof
curl --fail --silent --show-error --location --output M-1047-a3483808bb11802698c5f4ff1ea5e9eae0880408-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1047/a3483808bb11802698c5f4ff1ea5e9eae0880408/proof.json'
gh attestation verify M-1047-a3483808bb11802698c5f4ff1ea5e9eae0880408-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.ymlThis attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.
QR → receipt page