Sample
verify fastapi.middleware.cors.CORSMiddleware in pkg:pypi/fastapi@0.141.1
sha256:4f1ae2cdfbbcb739340fb3f1736c287b670dcb235245ca5ff56c0b8b19a5e76b
This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured.
How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people.
MIT-0
Execution evidence
The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.
- Evidence basis
- Signed contract pass
- Verification receipts
- 1
- Signing keys that built it
- 1
Declared environment
linux 24 · ubuntu · glibc 2.39 x64 pip
Verification-run environments
| Environment | Contract | Stages | Run |
|---|---|---|---|
| python 3.12 · linux alpine/x64 · docker ed25519:c1973797be207ac4 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · python@1python:3.12-alpine@sha256:d09d15e60962… |
2026-08-28 |
Case
HOW- Goal
- verify fastapi.middleware.cors.CORSMiddleware in pkg:pypi/fastapi@0.141.1
- Packages
- Symbols
-
- fastapi.middleware.cors.CORSMiddleware
- Created
- 2026-08-28T04:23:44Z
Contract
- assert CORSMiddleware adds access-control-allow-origin and credentials headers for allowed origin simple requests
- assert CORSMiddleware responds to preflight OPTIONS requests with allowed methods, headers, and max-age
- assert CORSMiddleware rejects preflight requests from disallowed origins with status 400
- assert CORSMiddleware supports regex origin matching via allow_origin_regex
- assert non-CORS requests without origin header pass through without CORS response headers
Files
- PROMPT.md
- csx.json
- pyproject.toml
- requirements.txt
- spec.json
- test/contract.py
Origin Seeder
anonymous