Docs · provider canary
Provider canary artefacts
The 1438 provider-canary writes machine-readable JSON via --out.
Committed artefact: app docs/canary/provider-canary.latest.json.
Exit 1 if any negative would pass. Cron: app
.github/workflows/provider-canary.yml (17 */6 * * *).
Default Actions GITHUB_TOKEN is enough for public
coderifts/demo; if the live job 403s, set
DEMO_READ_TOKEN.
Negatives
fake_issuer— same-name check from another appforged_signature— forged grant signaturecross_run— authentic grant from another runstale_head— green check on a stale headwrong_binding— grant bound elsewhererevoked_key— revoked issuer key
Positive — RAN (LOOP, not signed-witness)
positive_merge_under_grant is RAN.
Measured via gh:
coderifts/demo PR #14
(additive timezone) merged
2026-09-06T20:42:09Z.
Head bfe669539017738b3456b992c5f6a34121ba6659.
App 2860592 / coderifts
posted CodeRifts / contract-gate success.
Merge commit 971aea00dc043e13932bb2b4a84ed34b3b8b4c08 on main.
This is a green provider LOOP (real App, real check, real merge).
provider_witness stays carried_unsigned —
not a signed-witness 7/7 (phase-D option B, undecided).
It is a provider-integration claim, kept separate from the public conformance 7/7.
The public 7/7 is END_TO_END COVERED on
@coderifts/conformance@0.8.6 via a hermetic bare-Git
TARGET_STATE_TRANSITION_PROVEN
(proof_scope TRUSTED_EXECUTOR,
provider_witness NOT_APPLICABLE,
externally_witnessed false).
That is trusted-executor-integrity, not this GitHub loop and not PATH B.
Honesty table: What each proof proves.
Gate today vs roadmap (not available): claim table.