[doc] receipts · sha:7292d14c1aa3 · build:2026-08-18T00:08:45.256Z

Receipts.

Registry-backed public package claims below resolve to build-time artifacts. Public non-registry and research claims are labeled by attestation state. Product versions and commit SHAs below are fetched at build time from public registries with the persistent fetch cache disabled. If a secondary source is unavailable, the affected field is labeled unavailable instead of using a stale fallback.

[site] centennialsystems.com

Site attestation.

domain
centennialsystems.com
build-sha
7292d14c1aa3
build-time
2026-08-18T00:08:45.256Z
next-version
16.2.6
node-runtime-contract
>=20.20.1 <25
prebuilt-build-node-version
v22.22.3
vercel-node-function-runtime
nodejs24.x
vercel-python-function-runtime
python3.12
ssl-issuer
Let's Encrypt (Vercel-managed)

[build] source attestation

build-sha-full
7292d14c1aa39d6a05f3622c0f5be8c773e37d79
manifest
https://centennialsystems.com/manifest.json
security-txt
https://centennialsystems.com/.well-known/security.txt

[states] non-registry surfaces

Governed Agent Kernel · research
Standard: https://github.com/cjchanh/gak-conformance-standard · observed source SHA 80f491123a532b4055e58ca3de26054ecbbeaaf2. The public v1 Deponent badge is reproducible. Published v1.1 author-built certifications have zero third-party verdicts, fail current clean consistency checks, and lack exact code/source binding; published / not independently reproducible.
Archivist · external-only
External product authority; public CDS receipt pending SBOM/binary attestation.

[product] deponent

Deponent

[receipt-01]

pypi-package
deponent
pypi-url
https://pypi.org/project/deponent/
attestation-status
registry-backed
pypi-version
0.1.1
pypi-upload
2026-08-12T09:10:06.243144Z
license
Apache-2.0
github-repo
https://github.com/cjchanh/deponent
github-status
verified
github-sha
8e6704c6c7cc
github-sha-full
8e6704c6c7cc05eeaff15a5af7cb50fd96e35914
github-commit-date
2026-08-12T08:26:05Z
source-status
working-public-link
evidence
Public 0.1.1 release: PyPI artifacts and source commit verified.
boundary
use_jail=False proves policy and ledger behavior, not OS confinement. Docker is not live-verified. The badge is not an exact source or binary signature. Tamper-evident is not tamper-proof. Research prototype; not a security accreditation.

[product] mildoc-lint

mildoc-lint

[receipt-02]

pypi-package
mildoc-lint
pypi-url
https://pypi.org/project/mildoc-lint/
attestation-status
registry-backed
pypi-version
0.3.0
pypi-upload
2026-06-21T06:35:01.583773Z
license
Apache-2.0
github-repo
https://github.com/cjchanh/mildoc-lint
github-status
verified
github-sha
34c654d5590d
github-sha-full
34c654d5590df653b8d81c010b009f92f10844cc
github-commit-date
2026-08-03T19:39:19Z
source-status
working-public-link
evidence
Packaging regression fixed; isolated suite: 68 passed / 1 skipped.
boundary
Public HEAD CI is red on ruff; do not interpret the isolated suite as a green public build.

[product] sworncode

Sworncode

[receipt-03]

pypi-package
sworncode
pypi-url
https://pypi.org/project/sworncode/
attestation-status
registry-partial
pypi-version
0.4.0
pypi-upload
2026-03-06T22:57:59.163045Z
license
Apache-2.0
github-repo
unavailable
github-status
unavailable
github-sha
unavailable
github-sha-full
unavailable
github-commit-date
unavailable
source-status
known-broken-link
evidence
Published distribution; excluded from the current validator path.
boundary
PyPI project links are known broken. A security-boundary audit and corrected public release are pending; no Sworn success or clean fail-closed status is claimed.

[product] fleet-watch

Fleet Watch

[receipt-04]

pypi-package
fleet-watch
pypi-url
https://pypi.org/project/fleet-watch/
attestation-status
registry-partial
pypi-version
0.2.0
pypi-upload
2026-04-14T04:57:08.004435Z
license
MIT
github-repo
unavailable
github-status
unavailable
github-sha
unavailable
github-sha-full
unavailable
github-commit-date
unavailable
source-status
not-publicly-accessible
evidence
Published distribution; retained as qualified inventory only.
boundary
Its source repository is not publicly accessible; no public-source link or storefront CTA is offered.

[manifest]

The same data in machine-readable form: /manifest.json.