Current proof

Abizor exported Change Record artifacts from a real CI proof.

This proof summarizes PR #10: a GitHub Actions run where Abizor generated both machine-readable JSON and human-readable Markdown Change Record artifacts from the event log.

Date2026-06-09
Pull requestPR #10
Statusmerge boundary
Closureclosed, no merge

What was verified

Change Record is visible as a CI artifact.

GitHub Actions ran abizor ci-proof on PR #10 and wrote the replayable event log.

Abizor exported abizor-change-record.json and abizor-change-record.md artifacts.

The artifact manifest validated against the CI proof artifact manifest schema and recorded the Change Record artifact hashes.

Projection boundary

Event log is truth; Change Record is the read model.

Canonical truth remains the Abizor event log. The Change Record is a projection over that log for operators, reviewers, checks, proof reports, and future hosted surfaces.

The GitHub Check, publish receipt, summary, PR comment body, and manifest are also projections or evidence from the same CI run.

Artifact hashes

Public hash references for PR #10 artifacts.

Event log SHA-25649c0527b8ad459693d3dec7313a73078f1d58f77e5fdc70d01f875c1076a6915
Change Record JSON SHA-25620b789721fef7cd5b8dde73a16ea369e6e1e926683387a3d0c4a3d8bd80dbb99
Change Record Markdown SHA-2565542fa96dfd18ad205c0a6ad2bf52f44e24cb37277a04d57e47bc9ba88accab2
Manifest SHA-25698926a0d835b9cc4b508e47563db698c9306d007b0f1fd4452017d702c19c4d6

Reused projection

Summary and PR comment body shared one generated Markdown body.

In this v0 proof, abizor-summary.md and abizor-pr-comment.md intentionally reused the same generated Markdown projection.

Both artifacts had SHA-256 acf3ffaf5c5229fd55ec8dfbaa00b2a447dac00bd863e45814c6f756ad7a3285. That shared hash is recorded as reused projection, not as separate renderer evidence.

Boundary

What this proof does not claim.

This proof did not create, merge, or deploy the pull request.

It did not use a hosted app, hosted API, dashboard, billing flow, or GitHub App.

It is not a package-distribution, compliance, security-audit, regulated-enterprise, or production-deployment claim.