Manifest receipt

Locked & verifiable.

A pre-registered claim, anchored to a SHA-256 hash before the run. Anyone can re-derive it from the canonical bytes below.

SHA-2567b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8
Registered2026-07-11T21:40:03.894Z
Independent timestampRFC 3161 · 2026-07-11T22:19:23Z · timestamp.sigstore.dev (anchored after commit; earlier existence rests on the registry signature alone) · token
Transparency logRekor v2 · log2025-1.rekor.sigstore.dev · index 17336559 (entered after commit) · inclusion proof
Kindraw hash anchor — not a conforming PRML manifest (claim_id must be a UUIDv7 (schema pattern: version nibble 7, variant 8/9/a/b))
Submitted by@falsify
Manifest
version: prml/0.1
claim_id: 9545b6c1-8b3f-4312-b990-367d30c52977
created_at: '2026-07-11T21:39:31Z'
metric: conformance_vectors_passing
comparator: '>='
threshold: 21.0
dataset:
  id: prml-v0.1-test-vectors-json
  hash: cd7d22ee5bda1b5834c74f955fe3452b49e5357d5a7c9933805d0d0d99aa2a8e
seed: 1
producer:
  id: falsify.dev
raw bytes →
README badge
PRML locked[![PRML locked](https://registry.falsify.dev/badge/7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8.svg)](https://registry.falsify.dev/7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8)
Verify in CI
- uses: studio-11-co/prml-verify-action@v2 with: mode: verdict expected-hash: 7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8github.com/studio-11-co/prml-verify-action →

share on x →

Verify this hash yourself

Paste your manifest YAML. The canonical hash must match 7b0943184c45…. This runs the registry's own canonicalization module (canonical.js) in your browser; for verification that does not trust this registry at all, use any of the four reference implementations offline.

Verify the independent timestamp (RFC 3161, offline)

The token countersigns this manifest hash with the timestamp authority's key, so the time claim no longer rests on this registry. Verify with OpenSSL 3 (LibreSSL, the macOS default, cannot check the ESS extension):

curl -sO https://registry.falsify.dev/7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8.tsr
curl -s https://timestamp.sigstore.dev/api/v1/timestamp/certchain -o chain.pem
awk 'split_after==1{n++;split_after=0} /END CERTIFICATE/{split_after=1} {print > ("tsa-" n ".pem")}' n=0 chain.pem
openssl ts -verify -digest 7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8 \
  -in 7b0943184c4564c7c21193406d465861cd4ab2de60f517cf0f4fee1c34815db8.tsr -CAfile tsa-1.pem -untrusted tsa-0.pem

Expected output: Verification: OK.

What this receipt proves — and what it does not

PRML v0.2 is a frozen RFC (comment window closed 2026-05-22) — spec.falsify.dev/v0.2-rfc. Editor: spec.falsify.dev/editor.