Isolated hosted build
A pinned reusable workflow runs the build and signing steps in separate, fresh GitHub-hosted jobs. Application code has no signing permission.
Release identity, runtime readiness, and signed evidence from the live Numina verifier. Live runtime status is refreshed below; the dated build assessment identifies its exact artifacts.
Numina 4.0.0 brings the website, operations workspace and installable mobile web app together. Your service workflows and private Treasury records remain available in the same design.
Loading deployed release…
Loading…This build identity is calculated from the packaged application files. Detached build provenance is checked separately using the exact inventory fingerprint below. The rc26 runtime dependency retains its own identity and signed records.
Loading release requirements…
Recorded publication and journal evidence ↗ · Signed funding-plan receipt ↗
This section reads the deployed release inventory. It describes release-time records; it does not verify the contents of a receipt or replace the current NUSD status below. Private supporting documents stay in the authenticated Control panel.
A detached signed statement can identify the builder and the exact release file. The statement stays separate so the original file remains unchanged.
Signature verification has not been performed.
Loading…No manifest response is currently loaded.
The lookup opens GitHub’s public records for this fingerprint. A listed statement is evidence to verify; its presence alone does not establish a valid signature, SLSA level or deployment match. An empty or unavailable lookup does not verify the release.
Save the exact manifest above as application-release-v4.json. Use GitHub CLI to check its digest, the designated repository and the pinned builder identity.
Load the current manifest to prepare verification.
Review the verified source revision and workflow run against the intended release. A signature check does not by itself prove that these bytes were deployed or that all SLSA Build L3 controls are established.
Loading verified build record…
The source archive, Linux image archive and inventory have their own dated build evidence.
The recorded build produced a Linux image. Production hosting and financial execution are not established by that build. Current application capabilities are reported separately below.
UnavailableUnavailableUnavailableGitHub CLI verified these artifact signatures against the pinned builder and source revisions. This page checks the retained review and inventory fingerprints; it does not repeat Sigstore signature verification in the browser. The contract was a precompiled input. This record does not establish a security audit, reserves, custody, settlement or a new SLSA level.
Current application status unknown
UnknownMint preparation and recipient evidence guide ↗ · Read mint workflow
These fields come from the current public application status response. Enabled capabilities describe application configuration; transaction receipts and reserve evidence are separate. The canonical Numina treasury and private provider observations remain in their authenticated views.
Consulting services use the existing USD Stripe checkout after an authenticated request is saved. Review service scope and pricing ↗
The historical Numina 2.0.0 deployment archive and application inventory from GitHub Actions run 34717406980 · GitHub access required ↗ meet SLSA v1.2 Build Level 3 under our documented self-assessment, with verified builder-signed provenance.
4a7210c10fcfa79436018e8ba337244402661036https://slsa.dev/provenance/v1A pinned reusable workflow runs the build and signing steps in separate, fresh GitHub-hosted jobs. Application code has no signing permission.
The release check verified the signature, expected builder and source revisions, workflow run, and both artifact fingerprints.
The assessed inventory fingerprint is 30434a312366a8869b93e9f27b428ee0e5f385c1bd0e8fc877912a98fe97f792. These downloads preserve that completed build; the current release inventory above may identify a later build. Each later artifact requires its own signature and identity verification.
This is a build-artifact assessment, not third-party certification. It trusts GitHub’s hosted platform, Sigstore and the pinned builder. It does not assess subsequent hosting transformations, the separate rc26 runtime build, financial execution, reserve backing or native-store publication. The official slsa.dev predicate is also used for production.
SLSA requirements · Assessment guidance · GitHub build and attestation guidance.
rc26 control-plane runtime
Checking… files reported checked
Current runtime response
Verified in this browser
Checking…Checking…Checking…Checking…Checking…Checking…The release signature binds the production source, frozen core, SBOM and provenance hashes. These are compared with the pinned rc26 deployment. Source assembly provenance does not establish a hosted SLSA build level.
Download the responses fetched during this check. The manifest and attestation remain available through their original machine-readable APIs.
Waiting for a response.
The running service reports its supplied core validation result. Checking… historical conformance cases belong to the preserved rc20 report for this exact frozen core. No new rc26 conformance run is asserted.
Your browser verifies the runtime declaration and control-state receipts against the runtime key pinned in this website. The signed descriptor is matched to the pinned manifest. These signatures authenticate the runtime’s statements; they do not independently rerun release checks.
Artifact report: Checking…. The service publishes SBOM and provenance hashes. The deployed rc26 SBOM and provenance contents were matched to the assembled release. No SLSA build level is claimed for that separate rc26 runtime. The application artifact assessment above has its own scope.
The public verifier evaluates and signs policy decisions. The control plane works with internal records. These checks do not establish live-funds connectivity, financial balances, custody, or settlement.
The earlier web-adapter evidence remains available in the preserved control documentation. Historical rc20 evidence remains available through the rc20 manifest, SBOM and provenance. Its original hashes remain unchanged.
Bring a process, a constraint, or an integration challenge. We’ll discuss a scope that can be evaluated.
Numina 4 and the rc26 runtime bind the preserved 1.8.0 frozen core to the canonical Numina root across L1–L5. Core hashes and historical conformance retain their original scope. Native binaries retain their recorded signatures and store status.
Current rc26 source provenance does not claim SLSA Build L3. The highest Build level in SLSA v1.2 is L3; the retained L3 assessment applies only to its exact historical artifacts.