Current proof

Abizor verified a real Actions proof bundle locally.

This proof summarizes PR #11: GitHub Actions generated an Abizor CI proof bundle, the artifacts were downloaded, and abizor verify-proof proved that the manifest, hashes, and Change Record projections matched the canonical event log.

Date2026-06-10
Pull requestPR #11
Resultverified
Closureclosed, no merge

Proof spine

event log -> manifest -> Change Record -> verify-proof.

GitHub Actions produced the CI proof event log and artifact manifest.

Abizor exported machine-readable and human-readable Change Record artifacts from that event log.

The downloaded bundle was verified locally by recomputing hashes and replaying the Change Record from the event log.

Canonical truth

The event log remains the source of truth.

Canonical truth remains the Abizor event log. The artifact manifest, Change Record JSON, Change Record Markdown, GitHub Check, and this public proof page are projections or evidence outputs.

verify-proof did not ask GitHub whether the proof was valid. It verified the downloaded bundle locally against the event log and manifest.

Evidence

Downloaded artifact hashes.

Actions run27254173876
Head commitf4da6c9a8f68f6e9ff0c715175dc55807288ee18
Event log SHA-25652e11ae79d81bead4cf32acc47964a631bf4a3ca0b18fdc11503eb1c03df9098
Manifest SHA-2566bd33bcb572e65a2dc8fb4d4cf885a9f8e0e31193aaa4d2b9af956f5d5a07d43
Change Record JSON SHA-256fa342bb774beeec3759709c5fba50d820f98658824c1881945f7c9e272b909b8
Change Record Markdown SHA-256afb5d15e1c9de86f72f55a47928b5febec0e4803012ba978195fe2bd2ffacfc3

Output

The local verifier returned one short result.

verified: event log, manifest, and Change Record artifacts match

Boundary

What this proof does not claim.

This proof did not create, merge, or deploy code. PR #11 was closed without merge after the proof report was recorded.

It did not use a hosted app, hosted API, dashboard, billing flow, or GitHub App.

verify-proof did not call GitHub, network, shell, API, or hosted services.

It is not a compliance, security-audit, regulated-enterprise, or production-deployment claim.