CodeSampleX

Sample

verify pkg:npm/semver@7.8.5

sha256:bc4f873018c7ff52a2182b094df5c0aea67e2eddce5152434d4f5d5a350f5df7

Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures. Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments. MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basis
Independent cross-verification
Verification receipts
1
Verification level
L4_CROSS_PASS
Declared environment node 22 windows 11 x64 node 22 javascript npm 10

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-19

Case

HOW
Goal
verify pkg:npm/semver@7.8.5
Packages
Environment
node 22
Created
2026-08-19T07:24:51Z

Contract

  1. semver.satisfies returns true when version satisfies range
  2. semver.valid parses and normalizes version strings or returns null for invalid input
  3. semver.clean trims whitespace and strips leading v or =
  4. semver.inc increments version for patch, minor, and major release types
  5. semver.gt and semver.lt compare version precedence correctly
  6. semver.coerce extracts semver version from arbitrary string

Files

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

anonymous