CodeSampleX

Sample

verify pkg:npm/simple-update-notifier@2.0.0

sha256:de3fa6c379b5017d6828c2a5261af411e98e0c31fa578d14f4d47da2ef82a8ff

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1node:22-alpine@sha256:c610fcdfb1d5…
2026-08-28

Case

HOW
Goal
verify pkg:npm/simple-update-notifier@2.0.0
Packages
Created
2026-08-28T04:52:59Z

Contract

  1. simpleUpdateNotifier is an async function that checks for newer package versions from npm registry
  2. simpleUpdateNotifier opts out silently without network calls when stdout is not a TTY and alwaysRun is false
  3. simpleUpdateNotifier logs an update notification to stderr when a newer version is available and alwaysRun is true
  4. simpleUpdateNotifier persists lastUpdateCheck timestamp in XDG_CONFIG_HOME config directory
  5. simpleUpdateNotifier skips network check when last update check is within updateCheckInterval
  6. simpleUpdateNotifier does not log notification when latest registry version is equal to or older than current version
  7. simpleUpdateNotifier supports custom distTag parameter for targeting release tags like beta
  8. simpleUpdateNotifier catches network and parse errors gracefully without unhandled exceptions

Files

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • src/index.js
  • test/contract.js

Download the source artifact (tar.gz)

Origin Seeder

anonymous