KrickyKiki/oss-verified-test-fixture
github.com
attested 7778671d
Criteria
- ✓ dependency_licenses
- javascript: no runtime deps
- ✓ no_proprietary_blobs
- 6 tracked files inspected; no proprietary blobs found
- ✓ osi_license
- Declared 'MIT' resolves to OSI-approved leaves: MIT
- ✓ reuse
- 1 of 4 source files lack per-file SPDX headers, but a repo-level license declaration (LICENSE file or package.json) is present. Accepted as a blanket declaration.
Evidence
- commit_sha
- 7778671d43963d7f17b1096f2cfdba7b4ecb029d
- default_branch
- main
- attested_at
- 2026-05-14T16:49:50.575Z
- cli_version
- 0.1.3
- cli_sha
- cc90905fb61a641aa68bccd0664c9e31ecd99c7bec941030536dd7098419da63
- model_id
- claude-sonnet-4-6
- prompt_hash
- 043b9553d9184c6e5dda58fc56b857696aed63423b2897c88fd51d069e98b141
- sbom_hash
- e1e1b88f6cbdbce04a64011471c185775ade714a9c117ca15bf0bbb337a54786
- sbom_format
- cyclonedx-1.5
- LLM audit
- pass (3 passes) — 3/3 passes accepted
Sigstore identity
- oidc issuer
- https://token.actions.githubusercontent.com
- cert SAN
- https://github.com/KrickyKiki/oss-verified-test-fixture/.github/workflows/oss-verify.yml@refs/heads/main
- rekor logIndex
- 1538610561
Challenges (0 open / 0 total)
None filed. Anyone can challenge this badge:
curl -X POST https://$HOST/challenges/github/KrickyKiki/oss-verified-test-fixture \
-H 'content-type: application/json' \
-d '{
"commit_sha": "<40-hex SHA being challenged, optional>",
"evidence": "<markdown, <=4KB>",
"submitter_handle": "<optional contact>"
}'