Sample
verify pkg:maven/org.springframework.boot/spring-boot@4.1.0
sha256:bc8913398b0f583471b0342cd7dc7df88293fd223ca45bc26f5900c4910eed29
Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures.
Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments.
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
- Evidence basis
- Independent cross-verification
- Verification receipts
- 1
- Verification level
- L4_CROSS_PASS
Declared environment
- Execution context
- java 21
- Operating system
- linux 2023 · glibc
- Architecture
- x64
- Runtime
- java 21
- Language
- java 21
- Package manager
- maven 3
Verification-run environments
- Execution context
- java 21
- Operating system
- linux 2023 · amzn · glibc
- Architecture
- x64
- Runtime
- java 21
- Language
- java 21
- Package manager
- maven 3
- Execution
- container · docker
Case
HOW- Goal
- verify pkg:maven/org.springframework.boot/spring-boot@4.1.0
- Packages
-
- commons-logging/commons-logging 1.3.5
- io.micrometer/micrometer-commons 1.16.6
- io.micrometer/micrometer-observation 1.16.6
- org.jspecify/jspecify 1.0.0
- org.springframework.boot/spring-boot 4.1.0
- org.springframework/spring-aop 7.0.8
- org.springframework/spring-beans 7.0.8
- org.springframework/spring-context 7.0.8
- org.springframework/spring-core 7.0.8
- org.springframework/spring-expression 7.0.8
- Environment
- java 21
- Created
- 2026-08-18T12:33:15Z
Contract
- SpringBootVersion reports the pinned 4.1.0 implementation on the verified classpath.
- An option with a key and value is recognized in option names and returns its single parsed value.
- A flag option without an equals sign is recognized in option names and returns an empty list rather than null or a dummy string.
- An option assigned an empty string returns a list containing the empty string.
- Repeated options collect all assigned values in order.
- An unpassed option is absent from option names, returns false for containsOption, and returns null for getOptionValues.
- Positional arguments are excluded from option names and collected in order in getNonOptionArgs.
- getSourceArgs preserves the complete original raw command-line array.
Files
- PROMPT.md
- csx.json
- pom.xml
- spec.json
- src/Contract.java
Origin Seeder
anonymous
Verification receipts
-
java 21 · linux 2023/x64 · docker PASSed25519:2175b912ea1c23b1