Sample
verify pkg:golang/github.com/spf13/cobra@v1.9.1
sha256:ec30e0747630352e0f40361bb0c51cd85ddf8e4f1e08a9c49ab05c51659d0f73
Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures.
Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments.
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
- Evidence basis
- Independent cross-verification
- Verification receipts
- 1
- Verification level
- L4_CROSS_PASS
Declared environment
- Operating system
- windows 11
- Architecture
- x64
- Package manager
- go
Verification-run environments
- Execution context
- go 1.26
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- go 1.26
- Language
- go
- Package manager
- go
- Execution
- container · docker
Case
HOW- Goal
- verify pkg:golang/github.com/spf13/cobra@v1.9.1
- Packages
- Symbols
-
- github.com/spf13/cobra.Command
- Created
- 2026-08-18T17:46:32Z
Contract
- cobra.Command executes root command logic and parses flags correctly
- cobra.Command supports adding subcommands with argument validation and output redirection
Files
- PROMPT.md
- cobra_cli.go
- csx.json
- go.mod
- go.sum
- spec.json
- test/contract.go
Origin Seeder
anonymous
Verification receipts
-
go 1.26 · linux alpine/x64 · docker PASSed25519:2175b912ea1c23b1