Check this receipt without trusting this site

A copy-paste attestation command is unavailable because signed provenance has not been recorded for this receipt.

NORTHSET

Proof-of-Pass Receipt

Receipt ID M-1056

ISSUE / WORKIssue #110 · PR #119

CONTRIBUTOR SELF-RUN — NOT MAINTAINER VERIFICATION

RUN3.1s

01 / TECHNICAL RESULT

Technical result

2/2

declared commands passed

2/2 expected-success commands returned exit 0; all structured observations met their declared expectations

Upstream
OPENmutable external state
Environment
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8network none
Signature
proof attestedGitHub artifact attestation for the exact proof bytes

02 / DECLARED CHECKS

Command evidence

Execution summary
2/2 expected-success commands returned exit 0; all structured observations met their declared expectations

  1. npm test && npm run lint && npm run build

    exit 0 · 1.7s

  2. npm test && npm run lint && npm run build

    exit 0 · 1.2s

run wall (derived from recorded timestamps) 3.1s

Every command listed returned exit 0 in the declared environment. Only the listed commands are in scope. Unlisted test, lint, typecheck, build, coverage, compiler, full-suite, and CI gates are not implied or recorded.

03 / RECORDED IDENTITIES

Compact hashes

Patch diff SHA-256
sha256:14aa85…dbb8fc8
Container image digest
sha256:d52896…65563e8

04 / CLAIMS BOUNDARY

NOT INCLUDED

  • The integration suite was not run because it requires a live MinIO service; all 139 unit tests, lint, and build were run network-off.
  • This amendment changes tests only; the reviewed production implementation is unchanged.
  • Contributor self-run; not maintainer verification.
  • Does not prove code quality, security, full CI coverage, production readiness, or maintainer approval.
05 / Evidence annexTechnical · provenance · full recorded values
01

Technical evidence

Code, full environment, patch, and redacted outputs

Project

8thpark/geode

Work

Issue #110 · PR #119

Verification execution

runtime: Northset factory (node)
human operator: Northset mission operator

Code

base
1d5ab52e3461f3e2f52bc2f68d37155dae2ae30f
recorded patch commit
583e6c31b2be5bc807cc0086984e0d2dd95f7966
bound to verified tested tree
verified tested tree
78d7388b0a4e5917401db1dce7337fdb589b4bca
patch diff SHA-256
sha256:14aa85…dbb8fc8
bound to executed patch bytes

Environment

image reference
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8
repository digest
sha256:d52896…65563e8
network
none
02

Provenance & record

Full hashes, bundle identity, attestation, and record details

Record details

payment
none recorded · not merge-contingent
redactions
none recorded
Bundle contents digest
not recorded; raw proof identity is listed below
Immutable raw proof
inspect source proof
Raw proof SHA-256
sha256:926b67…8dce611
Publication observation
inspect source publication status
Factory PR state
OPEN
Factory CI state
PENDING
Factory attestation state
RECEIPT_ATTESTED
Factory status observed
Signed asset SHA-256
not recorded
Signed provenance recorded
not verified

Full cryptographic values

Full recorded values. The compact receipt above shortens these for legibility only.

Patch diff SHA-256
sha256:14aa85b793a2dbc846d0e6ca12ce7cd63ebd9e2282447a1d69877a4f2dbb8fc8
Container image digest
sha256:d5289634d7a51632a99b4796460f3235b5b91c0106cbffd1c74b0fd3b65563e8

Signed bundle

Attestation URL was not recorded.

QR → receipt page
Contributor self-run from immutable factory proof; not maintainer verification.

Evidence of what ran — not a verdict that the code is good.

SELF-FUNDED FIELD-TESTING.

- - - detach here - - -

External status

Mutable upstream observation; unattested and separate from the signed run record.

PR state
OPEN
Review signal
NONE
CI state
PENDING
Upstream updated
Observed
OPEN

Factory publication observation · open linked record

All Northset work in 8thpark/geode →

FOR MAINTAINERS

Maintain 8thpark/geode?

Get this same run for any PR in your queue — private, free during the pilot, nothing published without your approval.

The issue form is public. Do not include secrets or private repository details there; use email instead.

Already onboarded? Add northset-verify to a PR to request a run on that PR.

If your CI disagrees with this receipt, report it — we publish discrepancies on this ledger.

Claims boundary

This page reports scoped proof-of-pass receipt evidence. It does not prove code quality, security, full CI coverage, production readiness, or maintainer approval. An attestation confirms bundle provenance; it does not broaden the receipt's claim.

Read the full Claims Boundary policy.