Receipt · sip-conform@0.1.0
Pass · built from mainThis page was built from main. CI signs these exact bytes whenever the profile or the checker changes on main. The verify command below confirms the signature without trusting this site.
- Artifact
- protocol/profiles/sis.json
14 nodes, 10 edges, 1 projection, all public. Declared by Frank Riemer (GitHub: frankxai).
sha256
acac2fd23be17010ac9a4ea853aa40ef97c2fb0b4583f66b0cfe056ca5c5fd8a - Check that ran
sip-conform@0.1.0against SIP graph v0.1.0 (profile declares v0.1.0). 17 rules on graph structure, version compatibility, and what a public projection may show. The same check runs in sip-self-receipt.yml before anything is signed.- Verdict
- PASS · 17 of 17 rules passed
- Signer
- GitHub Actions workflow
.github/workflows/sip-self-receipt.ymlonrefs/heads/main, signing keyless through Sigstore with a GitHub OIDC identity. No long-lived key is involved. The signature covers the file's sha256; the receipt is the signed payload. - Timestamp
- Receipt recomputed when this page's copy was generated. The signing time is in the public Rekor transparency log; the verify command prints it with
--format json. - Verify it yourself
- verify command
gh attestation verify sis.json \ --repo frankxai/Starlight-Intelligence-System \ --predicate-type https://starlightintelligence.org/protocol/receipt/v0.1.0 \ --signer-workflow frankxai/Starlight-Intelligence-System/.github/workflows/sip-self-receipt.yml \ --source-ref refs/heads/mainRun it on a copy of the file (step 1 below). Exit code 0 means the signature is valid, the signer is that workflow on main, and the digest matches.
