Sample
verify pkg:golang/github.com/smallstep/truststore@v0.13.0
sha256:2e63723e5b2213269b530fb371cb9760cc4823d90f88e702d7f2d1e76a72696e
Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures.
Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments.
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
- Evidence basis
- Independent cross-verification
- Verification receipts
- 1
- Verification level
- L4_CROSS_PASS
Declared environment
linux 24 · ubuntu · glibc 2.39 x64 go
Verification-run environments
| Environment | Contract | Stages | Run |
|---|---|---|---|
| go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-21 |
Case
HOW- Goal
- verify pkg:golang/github.com/smallstep/truststore@v0.13.0
- Symbols
-
- github.com/smallstep/truststore.SaveCertificate
- github.com/smallstep/truststore.ReadCertificate
- Created
- 2026-08-21T00:04:10Z
Contract
- SaveCertificate writes an x509 certificate to PEM format on disk
- ReadCertificate parses an x509 certificate from PEM format on disk
- ReadCertificate returns an error for invalid or nonexistent certificate files
Files
- PROMPT.md
- csx.json
- go.mod
- go.sum
- spec.json
- test/contract_test.go
- truststore_sample.go
Origin Seeder
anonymous