[doc] receipts · sha:d1f7e5db94e0 · build:2026-09-05T04:50:27.713Z
Receipts.
Registry-backed public package claims below resolve to build-time artifacts. Public non-registry and research claims are labeled by attestation state. Product versions and commit SHAs below are fetched at build time from public registries with the persistent fetch cache disabled. If a secondary source is unavailable, the affected field is labeled unavailable instead of using a stale fallback.
[site] centennialsystems.com
Site attestation.
- domain
- centennialsystems.com
- build-sha
- d1f7e5db94e0
- build-time
- 2026-09-05T04:50:27.713Z
- next-version
- 16.2.6
- node-runtime-contract
- >=20.20.1 <25
- prebuilt-build-node-version
- v22.22.3
- vercel-node-function-runtime
- nodejs24.x
- vercel-python-function-runtime
- python3.12
- ssl-issuer
- Let's Encrypt (Vercel-managed)
[build] source attestation
- build-sha-full
- d1f7e5db94e025cb4dfd013d12e1d8a80e916296
- manifest
- https://centennialsystems.com/manifest.json
- security-txt
- https://centennialsystems.com/.well-known/security.txt
[states] non-registry surfaces
- Governed Agent Kernel · research
- Standard: https://github.com/cjchanh/gak-conformance-standard · observed source SHA 80f491123a532b4055e58ca3de26054ecbbeaaf2. The public v1 Deponent badge is reproducible. Published v1.1 author-built certifications have zero third-party verdicts, fail current clean consistency checks, and lack exact code/source binding; published / not independently reproducible.
- Archivist · external-only
- External product authority; public CDS receipt pending SBOM/binary attestation.
[product] deponent
Deponent
[receipt-01]
- pypi-package
- deponent
- pypi-url
- https://pypi.org/project/deponent/
- attestation-status
- registry-backed
- pypi-version
- 0.1.1
- pypi-upload
- 2026-08-12T09:10:06.243144Z
- license
- Apache-2.0
- github-repo
- https://github.com/cjchanh/deponent
- github-status
- verified
- github-sha
- 8e6704c6c7cc
- github-sha-full
- 8e6704c6c7cc05eeaff15a5af7cb50fd96e35914
- github-commit-date
- 2026-08-12T08:26:05Z
- source-status
- working-public-link
- evidence
- Public 0.1.1 release: PyPI artifacts and source commit verified.
- boundary
- use_jail=False proves policy and ledger behavior, not OS confinement. Docker is not live-verified. The badge is not an exact source or binary signature. Tamper-evident is not tamper-proof. Research prototype; not a security accreditation.
[product] mildoc-lint
mildoc-lint
[receipt-02]
- pypi-package
- mildoc-lint
- pypi-url
- https://pypi.org/project/mildoc-lint/
- attestation-status
- registry-backed
- pypi-version
- 0.3.0
- pypi-upload
- 2026-06-21T06:35:01.583773Z
- license
- Apache-2.0
- github-repo
- https://github.com/cjchanh/mildoc-lint
- github-status
- verified
- github-sha
- 34c654d5590d
- github-sha-full
- 34c654d5590df653b8d81c010b009f92f10844cc
- github-commit-date
- 2026-08-03T19:39:19Z
- source-status
- working-public-link
- evidence
- Packaging regression fixed; isolated suite: 68 passed / 1 skipped.
- boundary
- Public CI on main is passing (last run 2026-08-12); the isolated suite result is not a substitute for reading that run.
[product] sworncode
Sworncode
[receipt-03]
- pypi-package
- sworncode
- pypi-url
- https://pypi.org/project/sworncode/
- attestation-status
- registry-backed
- pypi-version
- 0.4.0
- pypi-upload
- 2026-03-06T22:57:59.163045Z
- license
- Apache-2.0
- github-repo
- https://github.com/cjchanh/sworn
- github-status
- verified
- github-sha
- 1ae83d7bf495
- github-sha-full
- 1ae83d7bf495ab6b4963d5ca358114a9494a9f1c
- github-commit-date
- 2026-08-25T18:35:14Z
- source-status
- working-public-link
- evidence
- Published distribution 0.4.0; public source repository verified at the observed SHA.
- boundary
- PyPI 0.4.0 metadata still points at a retired homepage domain and a GitHub org that does not exist; a corrected release is prepared in the repository but not published. No Sworn success or clean fail-closed status is claimed.
[product] fleet-watch
Fleet Watch
[receipt-04]
- pypi-package
- fleet-watch
- pypi-url
- https://pypi.org/project/fleet-watch/
- attestation-status
- registry-backed
- pypi-version
- 0.2.0
- pypi-upload
- 2026-04-14T04:57:08.004435Z
- license
- MIT
- github-repo
- https://github.com/cjchanh/fleet-watch
- github-status
- verified
- github-sha
- 140f2559eacc
- github-sha-full
- 140f2559eaccdbb4dbdb8eb051ae13b18dedb060
- github-commit-date
- 2026-09-04T23:27:24Z
- source-status
- working-public-link
- evidence
- Published distribution 0.2.0; public source repository verified at the observed SHA.
- boundary
- Public source; no independent validation, certification, or production-deployment claim is made.
[manifest]
The same data in machine-readable form: /manifest.json.