Sample
verify pkg:golang/github.com/google/uuid@v1.6.0
sha256:a9260653c357ca2d179b445c2d39cdf68ff39b04762311ec200f23e635f76e1d
Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures.
Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments.
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
- Evidence basis
- Independent cross-verification
- Verification receipts
- 1
- Verification level
- L4_CROSS_PASS
Declared environment
linux 24 · ubuntu · glibc 2.39 x64 go wsl
Verification-run environments
| Environment | Contract | Stages | Run |
|---|---|---|---|
| go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 | PASS | compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS CONTAINER_RUN · golang@1 |
2026-08-19 |
Case
HOW- Goal
- verify pkg:golang/github.com/google/uuid@v1.6.0
- Packages
- Symbols
-
- github.com/google/uuid.NewHash
- Created
- 2026-08-19T10:48:01Z
Contract
- assert uuid.NewHash with md5.New() and version 3 produces deterministic RFC 4122 Version 3 UUID identical to uuid.NewMD5
- assert uuid.NewHash with sha1.New() and version 5 produces deterministic RFC 4122 Version 5 UUID identical to uuid.NewSHA1
- assert uuid.NewHash with sha256.New() sets specified lower 4-bit version and RFC 4122 variant bits
- assert uuid.NewHash produces identical UUIDs for identical inputs and distinct UUIDs for different namespaces or payloads
- assert uuid.NewHash outputs format as valid 36-character hyphenated UUID strings and round-trip losslessly via uuid.Parse
Files
- PROMPT.md
- csx.json
- go.mod
- go.sum
- main.go
- spec.json
- test/contract.go
Origin Seeder
anonymous