{
  "schema": "neomorphic.evidence-record.v1",
  "record_id": "rec_hbDwOFwSshWPQhUTBwf-yDdQ",
  "record_type": "release_observation",
  "subject": {
    "type": "software_release",
    "id": "github:epistemedeus/agent-payment-integrity@v0.1.0-candidate.11",
    "display_name": "agent-payment-integrity v0.1.0-candidate.11"
  },
  "claim": {
    "statement": "The named public release candidate was observed in GitHub as a credential-free seller-conformance CLI and Action; the public source tree sets package.json private:true, and no npm package is published.",
    "scope": [
      "GitHub release v0.1.0-candidate.11",
      "public repository package metadata",
      "documented audit modes"
    ],
    "covered_versions": [
      "v0.1.0-candidate.11",
      "git 501a7381988782688bf8a16df3a9443c897dd30a"
    ]
  },
  "method": {
    "instrument": "Observatory",
    "version": "public-release-observation-v1",
    "mode": "observed",
    "checker": "Neomorphic LLC"
  },
  "result": {
    "status": "observed",
    "summary": "Neomorphic LLC performed this first-party observation of a Neomorphic-owned release candidate. The public GitHub surfaces support the bounded description recorded above; no independent release review is claimed.",
    "limitations": [
      "This record does not call the release stable or npm-published.",
      "Credential-free checks do not prove settlement, paid delivery, future availability, or general safety.",
      "The record does not claim an independent release review, independent adoption, revenue, or commercial demand."
    ]
  },
  "evidence": {
    "source_authority": "public GitHub release and repository metadata",
    "public_sources": [
      "https://github.com/epistemedeus/agent-payment-integrity/releases/tag/v0.1.0-candidate.11",
      "https://github.com/epistemedeus/agent-payment-integrity"
    ],
    "retained_summary": "Release tag, full commit identity, package.json private:true flag, absence of an npm publication, credential-free CLI and Action documentation, and GET-unpaid versus POST-contract-only boundary."
  },
  "issued_at": "2026-08-29T21:52:42Z",
  "observed_at": "2026-08-29T21:46:12Z",
  "expires_at": "2026-09-28T22:00:00Z",
  "supersedes": null,
  "revocation_url": "https://neomorphic.io/registry/rec_hbDwOFwSshWPQhUTBwf-yDdQ/#revocation",
  "evidence_digest": "sha256:47b8ddb705431d0680d6c9fe62ba902783ac1d7064c4966fca23cd38f933bff3",
  "signature": {
    "algorithm": "EdDSA",
    "canonicalization": "neomorphic-canonical-json-v1",
    "key_id": "neomorphic-evidence:S5luZKJSkSTS7ixne0SyHsylFf1CXNpR6-WrmZjy7c0",
    "value": "gsPanGqV-z4TPeiPbp2jQhccFmT7eNbwlYIL7clSXvzGIHni9E8PitBF3uqrKUcx72MrA6gTjrR2QmJm4F6sDg"
  }
}
