verify-core 0.13.0 (pinned 0.13.0); signer did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v content-open-1-A (content) #1 envelope integrity ok verified; recomputed ec1d2d13853e8c924b394e60a703efab2c62f5eadc0307d55a0735eec482b1c2 #2 signature ok valid (Ed25519ph) over the envelope hash ec1d2d13853e8c924b394e60a703efab2c62f5eadc0307d55a0735eec482b1c2 #3 canonicalization ok ok https://typedstandards.org/canonicalization/raw-bytes/v1 #4 content hash ok ok sha256 43a4dc139a3d473299cd2e4861ad80563491ac6b38df07e7d953b761cb8470f2 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label ok read: 'platform-export' (a signed label; nothing checks the mechanism) #12 type ok ok content/analysis/v1 #13 node id ok nodeId equals the bundle's packageHash #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note producerProfile_bundle_unresolved: 'platform-export' under 'hybrid/red-team-platform-export'; verify-core bundles no vocabulary for this profile #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names configuration (example) ok configurationHash recomputes from the signed values, as of 2026-10-03T22:35:50.999Z content-open-1-B (content) #1 envelope integrity ok verified; recomputed 29029a042c68423c05c18265414a27a87f3316a1210394e7d03de4809bdc988e #2 signature ok valid (Ed25519ph) over the envelope hash 29029a042c68423c05c18265414a27a87f3316a1210394e7d03de4809bdc988e #3 canonicalization ok ok https://typedstandards.org/canonicalization/raw-bytes/v1 #4 content hash ok ok sha256 98442cacc6b11d4e8749bdcc865b2d9a33f7bdca77d8a425b96baff3dabaacc4 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label ok read: 'platform-export' (a signed label; nothing checks the mechanism) #12 type ok ok content/analysis/v1 #13 node id ok nodeId equals the bundle's packageHash #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note producerProfile_bundle_unresolved: 'platform-export' under 'hybrid/red-team-platform-export'; verify-core bundles no vocabulary for this profile #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names configuration (example) ok configurationHash recomputes from the signed values, as of 2026-10-03T22:35:50.999Z content-open-2-C (content) #1 envelope integrity ok verified; recomputed a6d352477f1cc8d3f89d92d21422363ca23692b0dbb0054264dbfea9cd608a63 #2 signature ok valid (Ed25519ph) over the envelope hash a6d352477f1cc8d3f89d92d21422363ca23692b0dbb0054264dbfea9cd608a63 #3 canonicalization ok ok https://typedstandards.org/canonicalization/raw-bytes/v1 #4 content hash ok ok sha256 976ea52c6c2835baecafacda5c03266533fe59a9c810af2765dfc71266b5a569 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label ok read: 'platform-export' (a signed label; nothing checks the mechanism) #12 type ok ok content/analysis/v1 #13 node id ok nodeId equals the bundle's packageHash #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note producerProfile_bundle_unresolved: 'platform-export' under 'hybrid/red-team-platform-export'; verify-core bundles no vocabulary for this profile #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names configuration (example) ok configurationHash recomputes from the signed values, as of 2026-10-03T22:35:50.999Z content-open-2-D (content) #1 envelope integrity ok verified; recomputed 89b1068cf7cb7551f88d33d233b0cbcbc2c46fed3bafdaf61d372f3b51829927 #2 signature ok valid (Ed25519ph) over the envelope hash 89b1068cf7cb7551f88d33d233b0cbcbc2c46fed3bafdaf61d372f3b51829927 #3 canonicalization ok ok https://typedstandards.org/canonicalization/raw-bytes/v1 #4 content hash ok ok sha256 878f0c2c480d7319d8631047c16affa744fcd470b606d7aefbfcfb9daa3f204d #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label ok read: 'platform-export' (a signed label; nothing checks the mechanism) #12 type ok ok content/analysis/v1 #13 node id ok nodeId equals the bundle's packageHash #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note producerProfile_bundle_unresolved: 'platform-export' under 'hybrid/red-team-platform-export'; verify-core bundles no vocabulary for this profile #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names configuration (example) ok configurationHash recomputes from the signed values, as of 2026-10-03T22:35:50.999Z evaluates-open-3aa9a829-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed fe1c41954f220e2915c11905e31d7ac12def1d909e9aad7952d7f6da25f22d89 #2 signature ok valid (Ed25519ph) over the envelope hash fe1c41954f220e2915c11905e31d7ac12def1d909e9aad7952d7f6da25f22d89 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 90e5f44f9fe074b3e3c57e81f13550caf426ab97c5315fa4c6fd58d93275a85e #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-3aa9a829-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed 9a75425f54804a7b6aac171ffc459cb75428ae9161d41f61c120ea83e1eca55f #2 signature ok valid (Ed25519ph) over the envelope hash 9a75425f54804a7b6aac171ffc459cb75428ae9161d41f61c120ea83e1eca55f #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 1e7a8aa08e08894c5cd47ef639db6bb3cb1cfb084400f15c7f0baecdb2fc017f #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-7cf5b808-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed ea81d618b818987e1e0b29884e02d122bc1b6af672daa516b1a54bf58a4f6e6a #2 signature ok valid (Ed25519ph) over the envelope hash ea81d618b818987e1e0b29884e02d122bc1b6af672daa516b1a54bf58a4f6e6a #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 6e906e4a7373128370fe116b17b641ac65f4fc9124f6400042ebc94bfb3bbd31 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-7cf5b808-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed 6c13c9e279c99ffdab955df57f8daa2b16e9ee11ac08a663ef925d541e266a94 #2 signature ok valid (Ed25519ph) over the envelope hash 6c13c9e279c99ffdab955df57f8daa2b16e9ee11ac08a663ef925d541e266a94 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 02611e1a4e17db2fc648071733468843b1aa041742bfe2fec5a27fa8ffc23c4f #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-a747a62b-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed 3b5af83170318aecf078be001a175d72cd79a71c0073da9d08b72a63763ab88c #2 signature ok valid (Ed25519ph) over the envelope hash 3b5af83170318aecf078be001a175d72cd79a71c0073da9d08b72a63763ab88c #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 5565b6f6e87209174544e9af4d191e41a0c7a1481816d2962afb74840bb0a16b #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-a747a62b-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed 90488b716b72a1e139b45fe75388fdb081c731e1dfb67d36a60a58e011f8c66f #2 signature ok valid (Ed25519ph) over the envelope hash 90488b716b72a1e139b45fe75388fdb081c731e1dfb67d36a60a58e011f8c66f #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 ef0e5c8c1b68a9a3a06f162e1dc2d9a5fc803dff0953be5a51ffbf8523358b29 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-b0dfe392-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed 3e54a9a0b893015cd385a832fba3512c3b70b2c2ee99b90d40a89a30ea8653a2 #2 signature ok valid (Ed25519ph) over the envelope hash 3e54a9a0b893015cd385a832fba3512c3b70b2c2ee99b90d40a89a30ea8653a2 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 29a2cb29be65f9067d064f32fc6976d0c67c3074e64f59d8286a037f1f35ccbd #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-open-b0dfe392-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed d128cb92322d193765c37c53711e8f1d4c51859d06ad27fd97d2c5268a04050d #2 signature ok valid (Ed25519ph) over the envelope hash d128cb92322d193765c37c53711e8f1d4c51859d06ad27fd97d2c5268a04050d #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 ca6be41f6fd2ae5868b8224c4b73c59d6a43c4bb79f5d9ef32340897b5f4c212 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names content-sealed-1-E (content, sealed: the view alone) #1 envelope integrity n/a unavailable (private): the package is withheld by design, so there is nothing to recompute; not altered #2 signature ok valid (Ed25519ph) over the envelope hash a8a4bc9c64a481e220a8cfba90ddccbfd7282ea6594b09d232d8ccb823bf11ee #3 canonicalization n/a no package #4 content hash n/a no package; the view states contentHash.sha256 2e67ead8319214ee91a35100daefde2bfe73bb4843d9c5ce554fff9507000994 #5 key status note registry_unavailable: without the package the key-derived check does not run, and no registry is supplied (G0 D2); see "same key" below #6 signingKeyId n/a no package #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no package #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label ok read: 'platform-export' (from the unsigned view; the signed label is in the withheld package) #12 type n/a no package; the view states content/analysis/v1 #13 node id n/a no package to recompute; the view's packageHash is the id the verdicts name #14 signer identity n/a no package #15 captureMethod vocab n/a no package #16 content profile n/a no package same key (example) ok the signature's key derives the identifier package/signer.json names, and so does the view's signer claim, which is unsigned evaluates-sealed-60125583-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed 1aa88a5aa4e0bdc06cedd6a44b286aaa0d3760d4624dceca9144f2d9c331a505 #2 signature ok valid (Ed25519ph) over the envelope hash 1aa88a5aa4e0bdc06cedd6a44b286aaa0d3760d4624dceca9144f2d9c331a505 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 85628cf6d3697e272f6d7370dd8b2c0d8b40409c4df49bb573b52498cfef0c78 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-sealed-60125583-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed 36af6c4ea7185e3758bbed76f2ffdac5b9265e3cae625029170d969dd3eb1d64 #2 signature ok valid (Ed25519ph) over the envelope hash 36af6c4ea7185e3758bbed76f2ffdac5b9265e3cae625029170d969dd3eb1d64 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 00aaa3fcee667d575224943b7d019b09592902db5ab609f3cf1dc75620933995 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-sealed-de6282c8-reviewer-2 (evaluates) #1 envelope integrity ok verified; recomputed ba6e5b90a5a1d5ad66cb83a4fc19b8e7d291f4f39a7655da8723c7dadcbffa1d #2 signature ok valid (Ed25519ph) over the envelope hash ba6e5b90a5a1d5ad66cb83a4fc19b8e7d291f4f39a7655da8723c7dadcbffa1d #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 f6dc0f761ac82e0c13f2a66ec29949b0f4cb6203867e0ed04f15da4b3a94897b #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names evaluates-sealed-de6282c8-reviewer-1 (evaluates) #1 envelope integrity ok verified; recomputed ee9b9d48c00cb98e775529f5cfe16f345ff4842d27c8be852b78b0dd0dd5ec01 #2 signature ok valid (Ed25519ph) over the envelope hash ee9b9d48c00cb98e775529f5cfe16f345ff4842d27c8be852b78b0dd0dd5ec01 #3 canonicalization ok ok https://typedstandards.org/canonicalization/legacy-json/v1 #4 content hash ok ok sha256 29ecae31602b668408417a0f27d674f0053d6cfe69decdf1859f57c4320e0547 #5 key status note self_certified: the identifier is derived from the signing key; no registry vouches for it (G0 D2) #6 signingKeyId ok ok: kid equals metadata.signingKeyId #7 RFC 3161 timestamp n/a no token: external proofs wait for G2 (G0 D3) #8 Rekor inclusion n/a no entry: external proofs wait for G2 (G0 D3) #9 BlobRef n/a no BlobRef: the output is inline #10 lifecycle ok active: no lifecycle attestation is carried #11 captureMethod label n/a none carried #12 type ok ok attestation/evaluates/v1 #13 node id ok nodeId equals the bundle's packageHash; targetNodeId resolves to a bundle here #14 signer identity ok key_derived_match: did:key:z6MkvfGn34RnbEAE3LdNSrhtYQFmoMNFBLZ4XnYow4qcz37v #15 captureMethod vocab note no_capture_method: produce-core's attestation builder emits none (docs/findings.md) #16 content profile ok contentProfile_absent, read as default same key (example) ok the signature's key derives the identifier package/signer.json names verdicts content-open-1-A ok 2 verdict(s) name it; successful_exploit 2 true, 0 false content-open-1-B ok 2 verdict(s) name it; successful_exploit 2 true, 0 false content-open-2-C ok 2 verdict(s) name it; successful_exploit 2 true, 0 false content-open-2-D ok 2 verdict(s) name it; successful_exploit 2 true, 0 false content-sealed-1-E ok 4 verdict(s) name it; successful_exploit 2 true, 2 false; its transcript is withheld network fetch calls: 0 result: all checks passed