Manifest receipt

Locked & verifiable.

A pre-registered claim, anchored to a SHA-256 hash before the run. Anyone can re-derive it from the canonical bytes below.

SHA-2565a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0
Registered2026-05-16T12:36:09.873Z
Independent timestampRFC 3161 · 2026-07-11T22:19:17Z · timestamp.sigstore.dev (anchored after commit; earlier existence rests on the registry signature alone) · token
Transparency lognot yet in a public log (record predates full-manifest storage; RFC 3161 token only)
Kindcommitted before 2026-07-11 — not validated at commit time; re-verify offline with a reference implementation
Submitted by@onboarding-test
Manifest preview
version: "prml/0.1"
claim_id: "01910000-0000-7000-8000-000000000005"
created_at: "2026-05-17T12:00:00Z"
metric: "accuracy"
comparator: ">="
threshold: 0.85
dataset:
  id: "imagenet-val-2012"
  hash: "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"
seed: 42
producer:
  id: "onboarding-walkthrough-test"
Note (2026-07-11): records committed before this date stored only a 500-byte preview, so this page cannot prove the full manifest. Re-verify offline against the original file.
README badge
PRML locked[![PRML locked](https://registry.falsify.dev/badge/5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0.svg)](https://registry.falsify.dev/5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0)
Verify in CI
- uses: studio-11-co/prml-verify-action@v2 with: mode: verdict expected-hash: 5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0github.com/studio-11-co/prml-verify-action →

share on x →

Verify this hash yourself

Paste your manifest YAML. The canonical hash must match 5a048172ef02…. This runs the registry's own canonicalization module (canonical.js) in your browser; for verification that does not trust this registry at all, use any of the four reference implementations offline.

Verify the independent timestamp (RFC 3161, offline)

The token countersigns this manifest hash with the timestamp authority's key, so the time claim no longer rests on this registry. Verify with OpenSSL 3 (LibreSSL, the macOS default, cannot check the ESS extension):

curl -sO https://registry.falsify.dev/5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0.tsr
curl -s https://timestamp.sigstore.dev/api/v1/timestamp/certchain -o chain.pem
awk 'split_after==1{n++;split_after=0} /END CERTIFICATE/{split_after=1} {print > ("tsa-" n ".pem")}' n=0 chain.pem
openssl ts -verify -digest 5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0 \
  -in 5a048172ef02e3afb8ec87ad7ec8efffbd87ff021a2773437e955e17dc14ead0.tsr -CAfile tsa-1.pem -untrusted tsa-0.pem

Expected output: Verification: OK.

What this receipt proves — and what it does not

PRML v0.2 is a frozen RFC (comment window closed 2026-05-22) — spec.falsify.dev/v0.2-rfc. Editor: spec.falsify.dev/editor.