Check this receipt without trusting this site

Factory proof attestation for the exact immutable proof bytes.

curl --fail --silent --show-error --location --output M-1048-16aa11b96d9e4d88afe8c6c4c5306de9ec8850de-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1048/16aa11b96d9e4d88afe8c6c4c5306de9ec8850de/proof.json'
gh attestation verify M-1048-16aa11b96d9e4d88afe8c6c4c5306de9ec8850de-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.yml

Expected output includes Verification succeeded!

NORTHSET

Proof-of-Pass Receipt

Receipt ID M-1048

ISSUE / WORKIssue #6551 · PR #8801

CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION

RUN1s

01 / TECHNICAL RESULT

Technical result

1/1

declared command passed

1/1 expected-success command returned exit 0; all structured observations met their declared expectations

Upstream
MERGEDmutable external state
Environment
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8network none
Signature
proof attestedGitHub artifact attestation for the exact proof bytes

02 / DECLARED CHECKS

Command evidence

Execution summary
1/1 expected-success command returned exit 0; all structured observations met their declared expectations

  1. node -e 'const fs=require("fs");const s=fs.readFileSync("src/cljs/nr/gameboard/board.cljs","utf8");const calls=(s.match(/replay-opponent-hand\?/g)||[]).length;if(!s.includes("(defn replay-opponent-hand?")||!s.includes("[facedown-card (:side card)]")||calls<3){console.error("replay opponent hand visibility predicate is missing");process.exit(1)}'

    exit 0 · 0.3s

run wall (derived from recorded timestamps) 1s

Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.

03 / RECORDED IDENTITIES

Compact hashes

Patch diff SHA-256
sha256:755eb8…7848530
Container image digest
sha256:d52896…65563e8

04 / CLAIMS BOUNDARY

NOT INCLUDED

  • Manual replay UI verification was not run.
  • Contributor self-run; not maintainer verification.
  • Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01

Technical evidence

Code, full environment, patch, and redacted outputs

Project

mtgred/netrunner

Work

Issue #6551 · PR #8801

Verification execution

runtime: Northset factory (node)
human operator: Northset mission operator

Code

base
e5ca7339c5566808b1ccd190d088ad0caec0031f
recorded patch commit
16aa11b96d9e4d88afe8c6c4c5306de9ec8850de
bound to verified tested tree
verified tested tree
e3d89b854084a7d8b2dea4d7179a1bfddca09723
patch diff SHA-256
sha256:755eb8…7848530
bound to executed patch bytes

Environment

image reference
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8
repository digest
sha256:d52896…65563e8
network
none
02

Provenance & record

Full hashes, bundle identity, attestation, and record details

Record details

payment
none recorded · not merge-contingent
redactions
none recorded
Bundle contents digest
not recorded; raw proof identity is listed below
Immutable raw proof
inspect source proof
Raw proof SHA-256
sha256:4aae67…46351da
Publication observation
inspect source publication status
Factory PR state
MERGED
Factory attestation state
RECEIPT_ATTESTED
Factory status observed
Factory proof attestation
recorded for the exact proof bytes

Full cryptographic values

Full recorded values. The compact receipt above shortens these for legibility only.

Patch diff SHA-256
sha256:755eb8d43c01147b2adfab6266dde193897d7cde6e8e6c690d00681037848530
Container image digest
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8

Factory proof attestation

Open factory proof attestation

Verify the factory proof

curl --fail --silent --show-error --location --output M-1048-16aa11b96d9e4d88afe8c6c4c5306de9ec8850de-proof.json 'https://raw.githubusercontent.com/northset-oss/verification-pilot/1899d890df7156ab758a6c0449fe7bbbc3f46710/receipts/M-1048/16aa11b96d9e4d88afe8c6c4c5306de9ec8850de/proof.json'
gh attestation verify M-1048-16aa11b96d9e4d88afe8c6c4c5306de9ec8850de-proof.json --repo northset-oss/verification-pilot --signer-workflow northset-oss/verification-pilot/.github/workflows/pages.yml

This attestation covers the exact immutable factory proof bytes. It does not attest a legacy signed bundle, witness the recorded run, or turn contributor evidence into maintainer verification.

QR → receipt page
Contributor self-run from immutable factory proof; not maintainer verification.

Evidence of what ran — not a verdict that the code is good.

SELF-FUNDED FIELD-TESTING.

- - - detach here - - -

External status

Mutable upstream observation; unattested and separate from the signed run record.

PR state
MERGED
GitHub review decision
NONE
Upstream updated
Observed
MERGED

Factory publication observation · open linked record

All Northset work in mtgred/netrunner →

FOR MAINTAINERS

Maintain mtgred/netrunner?

Get this same run for any PR in your queue — private, free during the pilot, nothing published without your approval.

The issue form is public. Do not include secrets or private repository details there; use email instead.

Already onboarded? Add northset-verify to a PR to request a run on that PR.

Claims boundary

This page reports scoped proof-of-pass receipt evidence. It does not prove code quality, security, full CI coverage, production readiness, or maintainer approval. The factory proof attestation is bound to the exact proof bytes. It does not attest a legacy signed bundle or broaden the receipt's claim.

Read the full Claims Boundary policy.