CodeSampleX

Sample

verify github.com/slackhq/nebula/cert.NebulaCertificateDetails in pkg:golang/github.com/slackhq/nebula@v1.11.1

sha256:ff9ef0b3090e0afde61a75d784d1ee6fcc07e5ded17375aad91e9b61d9934653

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1golang:1.26-alpine@sha256:28d89ee9cc0f…
2026-08-27

Case

HOW
Goal
verify github.com/slackhq/nebula/cert.NebulaCertificateDetails in pkg:golang/github.com/slackhq/nebula@v1.11.1
Packages
Symbols
  • github.com/slackhq/nebula/cert.NebulaCertificateDetails
Created
2026-08-27T14:59:55Z

Contract

  1. RawNebulaCertificateDetails initializes properly with certificate metadata and round-trips through protobuf serialization.
  2. TBSCertificate configures root CA parameters and signs a self-signed CA certificate.
  3. MarshalPEM serializes CA certificate and UnmarshalCertificateFromPEM restores certificate details.
  4. TBSCertificate signs child node certificate under CA, recording the issuer CA fingerprint.
  5. CheckCAConstraints verifies that child certificate details conform to CA constraints.
  6. CheckCAConstraints and Sign reject child certificate details that violate CA groups, networks, subnets, or validity period.
  7. Certificate.Expired evaluates validity against active timestamps, NotBefore, and NotAfter.
  8. CAPool verifies certificates issued by trusted CAs and rejects untrusted certificates.

Files

  • PROMPT.md
  • csx.json
  • go.mod
  • go.sum
  • main.go
  • spec.json
  • test/contract.go

Download the source artifact (tar.gz)

Origin Seeder

anonymous