receipt · thought-trails

reading room · 416 words · 2 min

Repository verification: thought-trails

Trust receipt for Repository verification: thought-trails: Repository verification summarized 3 passing check(s) against truth schema 0.7.0 with visible gaps. Includes checks, evidence, exclusions, freshness, and limitations.

Trust Receipt

trust receipt checks passed with limitations

This limitation-forward receipt summarizes bounded repository checks. It is not a certification, and it can say I don't know when evidence is missing.

Verdict

passed Repository verification summarized 3 passing check(s) against truth schema 0.7.0 with visible gaps.

Freshness

fresh 2026-07-10T12:26:04Z

Checks

7 3 passed, 0 failed, 4 not checked, 0 inconclusive

Receipt ID

tr_verify_thought-trails 2026-07-10T12:26:13Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Not Checked

  • Ci Present not checked

  • not_applicable: no CI workflows detected

    • outcome=not_applicable

    • derived_has_ci=False

  • portfolio-verification-checkrun

  • Ci Green not checked

  • not_applicable: CI was not detected

    • outcome=not_applicable
  • portfolio-verification-checkrun

  • Claims Match not checked

  • not_applicable: no mechanically checkable claims found

    • outcome=not_applicable

    • ledger_count=0

  • portfolio-verification-checkrun

  • Liveness not checked

  • not_applicable: liveness only applies to web-deploy stack

    • outcome=not_applicable
  • portfolio-verification-checkrun

Passed

  • Tests Present passed

  • pass: truth data reports a test suite

    • outcome=pass

    • derived_has_tests=True

  • portfolio-verification-checkrun

  • Tests Pass passed

  • pass: test command exited 0

    • outcome=pass

    • cmd=/bin/zsh -lc npm ci && npm test && cargo test --locked --manifest-path src-tauri/Cargo.toml

    • duration_s=8.358

    • failed=0

    • passed=16

    • total=16

  • portfolio-verification-checkrun

  • License Present passed

  • pass: truth data reports a license file

    • outcome=pass

    • derived_has_license=True

  • portfolio-verification-checkrun

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

ID Title Kind Reference Digest
portfolio-verification-checkrun Portfolio repository verification check-run json local-public-safe-input:portfolio-verification-checkrun 2e51f6182143f461...

Intentionally Excluded

Local filesystem paths and raw logsThe receipt includes bounded outcomes, counts, and short reasons only.

Secrets and private configurationThe check-run contract excludes credentials, token values, environment dumps, and private config.

Mutable repository stateThe runner is read-only for target repositories and does not record unbounded working-tree detail.

Limitations

A receipt is not a certification, approval, or live health guarantee.

External checks depend on local CLI availability, network access, and current provider state.

Claims matching is limited to mechanically checkable README signals in v1.

Passing checks do not prove security posture, maintainability, or release readiness.

Reproduce Or Inspect

Run a bounded portfolio verification check-run.python3 scripts/portfolio_verify_run.py --repo-id --repo-path --repo-full-name <owner/name> --stack --truth <truth.json> --out <check-run.json>

Generate this receipt.trust-receipt repo-verify --input <check-run.json>

Payload SHA-256: fd49c4727be5694e6824099aed0c24f94bd6e566a64411fa124c484cb442594d

Generated by trust-receipt-generator 0.1.0

payload sha-256 · fd49c4727be5694e6824099aed0c24f94bd6e566a64411fa124c484cb442594d