Trust Receipt trust receiptpartial proof with gaps

Repository verification: Synthetic Portfolio Repo Fixture

This limitation-forward receipt summarizes bounded repository checks. It is not a certification, and it can say I don't know when evidence is missing.

Verdict
mixed
Repository verification summarized 5 passing check(s) against truth schema 0.7.0 with visible gaps.
Freshness
static_fixture
2026-06-29T10:00:00Z
Checks
7
5 passed, 0 failed, 1 not checked, 1 inconclusive
Receipt ID
tr_verify_synthetic_portfolio_repo
2026-06-29T12:00:00Z

Boundary

This receipt is not a safety certification, security approval, or live health guarantee. It summarizes the public-safe evidence, checks, exclusions, freshness, and limitations listed below.

Inconclusive

Liveness
inconclusive
cannot_verify: no deploy alias provided
  • outcome=cannot_verify
  • alias=synthetic.example.test
  • limitation=No deploy alias was inspected for the synthetic fixture.
portfolio-verification-checkrun

Not Checked

License Present
not checked
not_applicable: no license file detected
  • outcome=not_applicable
  • derived_has_license=False
portfolio-verification-checkrun

Passed

Tests Present
passed
pass: synthetic truth data reports a test suite
  • outcome=pass
  • derived_has_tests=True
portfolio-verification-checkrun
Tests Pass
passed
pass: synthetic test summary exited 0
  • outcome=pass
  • cmd=pytest -q
  • duration_s=2.5
  • failed=0
  • passed=12
  • total=12
portfolio-verification-checkrun
Ci Present
passed
pass: synthetic truth data reports CI workflows
  • outcome=pass
  • derived_has_ci=True
portfolio-verification-checkrun
Ci Green
passed
pass: synthetic latest default-branch workflow succeeded
  • outcome=pass
  • conclusion=success
  • run_url=https://github.com/example/synthetic-portfolio-repo/actions/runs/100
portfolio-verification-checkrun
Claims Match
passed
pass: one synthetic bounded claim was corroborated
  • outcome=pass
  • ledger_count=1
portfolio-verification-checkrun

Evidence

Evidence entries are public-safe references and digests, not raw private reports.

IDTitleKindReferenceDigest
portfolio-verification-checkrunPortfolio repository verification check-runjsonlocal-public-safe-input:portfolio-verification-checkrun9d9001feb86bc084...

Intentionally Excluded

Local filesystem paths and raw logs
The receipt includes bounded outcomes, counts, and short reasons only.
Secrets and private configuration
The check-run contract excludes credentials, token values, environment dumps, and private config.
Mutable repository state
The runner is read-only for target repositories and does not record unbounded working-tree detail.

Limitations

A receipt is not a certification, approval, or live health guarantee.
External checks depend on local CLI availability, network access, and current provider state.
Claims matching is limited to mechanically checkable README signals in v1.
Passing checks do not prove security posture, maintainability, or release readiness.

Reproduce Or Inspect

Run a bounded portfolio verification check-run.
python3 scripts/portfolio_verify_run.py --repo-id <repo> --repo-path <repo> --repo-full-name <owner/name> --stack <stack> --truth <truth.json> --out <check-run.json>
Generate this receipt.
trust-receipt repo-verify --input <check-run.json>