{"schema_version":"cds-attestation-v1","site":{"domain":"centennialsystems.com","build_sha":"7292d14c1aa39d6a05f3622c0f5be8c773e37d79","build_sha_short":"7292d14c1aa3","build_time":"2026-08-18T00:08:45.256Z","next_version":"16.2.6","node_runtime_contract":">=20.20.1 <25","node_version":"v22.22.3","ssl_issuer":"Let's Encrypt (Vercel-managed)","node_version_scope":"prebuilt-build","vercel_node_function_runtime":"nodejs24.x","vercel_python_function_runtime":"python3.12"},"products":[{"attestation_status":"registry-backed","name":"Deponent","pypi_package":"deponent","pypi_url":"https://pypi.org/project/deponent/","pypi_version":"0.1.1","license":"Apache-2.0","pypi_upload_time":"2026-08-12T09:10:06.243144Z","github_repo":"https://github.com/cjchanh/deponent","github_status":"verified","github_sha":"8e6704c6c7cc05eeaff15a5af7cb50fd96e35914","github_sha_short":"8e6704c6c7cc","github_commit_date":"2026-08-12T08:26:05Z","source_status":"working-public-link","evidence":"Public 0.1.1 release: PyPI artifacts and source commit verified.","boundary":"use_jail=False proves policy and ledger behavior, not OS confinement. Docker is not live-verified. The badge is not an exact source or binary signature. Tamper-evident is not tamper-proof. Research prototype; not a security accreditation."},{"attestation_status":"registry-backed","name":"mildoc-lint","pypi_package":"mildoc-lint","pypi_url":"https://pypi.org/project/mildoc-lint/","pypi_version":"0.3.0","license":"Apache-2.0","pypi_upload_time":"2026-06-21T06:35:01.583773Z","github_repo":"https://github.com/cjchanh/mildoc-lint","github_status":"verified","github_sha":"34c654d5590df653b8d81c010b009f92f10844cc","github_sha_short":"34c654d5590d","github_commit_date":"2026-08-03T19:39:19Z","source_status":"working-public-link","evidence":"Packaging regression fixed; isolated suite: 68 passed / 1 skipped.","boundary":"Public HEAD CI is red on ruff; do not interpret the isolated suite as a green public build."},{"attestation_status":"registry-partial","name":"Sworncode","pypi_package":"sworncode","pypi_url":"https://pypi.org/project/sworncode/","pypi_version":"0.4.0","license":"Apache-2.0","pypi_upload_time":"2026-03-06T22:57:59.163045Z","github_repo":"unavailable","github_status":"unavailable","github_sha":"unavailable","github_sha_short":"unavailable","github_commit_date":"unavailable","source_status":"known-broken-link","evidence":"Published distribution; excluded from the current validator path.","boundary":"PyPI project links are known broken. A security-boundary audit and corrected public release are pending; no Sworn success or clean fail-closed status is claimed."},{"attestation_status":"registry-partial","name":"Fleet Watch","pypi_package":"fleet-watch","pypi_url":"https://pypi.org/project/fleet-watch/","pypi_version":"0.2.0","license":"MIT","pypi_upload_time":"2026-04-14T04:57:08.004435Z","github_repo":"unavailable","github_status":"unavailable","github_sha":"unavailable","github_sha_short":"unavailable","github_commit_date":"unavailable","source_status":"not-publicly-accessible","evidence":"Published distribution; retained as qualified inventory only.","boundary":"Its source repository is not publicly accessible; no public-source link or storefront CTA is offered."}],"non_registry_attestation_states":[{"surface":"Governed Agent Kernel","state":"research","note":"Standard: https://github.com/cjchanh/gak-conformance-standard · observed source SHA 80f491123a532b4055e58ca3de26054ecbbeaaf2. The public v1 Deponent badge is reproducible. Published v1.1 author-built certifications have zero third-party verdicts, fail current clean consistency checks, and lack exact code/source binding; published / not independently reproducible."},{"surface":"Archivist","state":"external-only","note":"External product authority; public CDS receipt pending SBOM/binary attestation."}],"links":{"receipts_page":"https://centennialsystems.com/receipts","security_txt":"https://centennialsystems.com/.well-known/security.txt","sitemap":"https://centennialsystems.com/sitemap.xml"}}