CodeSampleX

Sample

verify github.com/smallstep/scep.PKIMessage in pkg:golang/github.com/smallstep/scep@v0.0.0-20231024192529-aee96d7ad34d

sha256:6ba1a0abdb0bc17ea60167b8eade3dbd1fe8f3b7a974df53bb452e5d51899154

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26-alpine@sha256:28d89ee9cc0f…
2026-08-27

Case

HOW
Goal
verify github.com/smallstep/scep.PKIMessage in pkg:golang/github.com/smallstep/scep@v0.0.0-20231024192529-aee96d7ad34d
Packages
Symbols
  • github.com/smallstep/scep.PKIMessage
Created
2026-08-27T10:56:58Z

Contract

  1. scep.NewCSRRequest creates a SCEP PKCSReq message encapsulating a PKCS#10 CSR with signer and recipient certificates
  2. scep.ParsePKIMessage decodes a raw PKCS#7 envelope to extract messageType, transactionID, and senderNonce
  3. scep.PKIMessage.DecryptPKIEnvelope decrypts the encrypted CSR payload using CA private key and certificate
  4. scep.PKIMessage.Success constructs an encrypted CertRep response with SUCCESS status for the issued certificate
  5. scep.PKIMessage.Fail constructs a signed CertRep response with FAILURE status and specified FailInfo
  6. scep.DegenerateCertificates and scep.CACerts encode and decode certificate chains in degenerate PKCS#7 format
  7. scep.NewCSRRequest returns an error when no recipient certificates are provided
  8. scep.ParsePKIMessage returns an error when given invalid or corrupt data

Files

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

Download the source artifact (tar.gz)

Origin Seeder

anonymous