{
  "generated_at": "2026-09-10T17:07:21.133335+00:00",
  "candidate": "32a73dfa6d8d6903555e5902d8a50f39485a6b2c",
  "run_url": "https://github.com/geoknoesis/trustweave/actions/runs/34504432177",
  "local_tests": {
    "tests": 3910,
    "failures": 0,
    "errors": 0,
    "skipped": 15
  },
  "hosted_tests": {
    "tests": 3909,
    "failures": 0,
    "errors": 0,
    "skipped": 15
  },
  "tool_tests": 55,
  "reference_tests": 326,
  "conformance": {
    "python_cases": 26,
    "reverse_profiles": 3,
    "reference_outcomes": 65,
    "explained_differences": 2
  },
  "ledger_model_transitions": 214,
  "source_examples": 9,
  "example_entry_points": 24,
  "required_tests": 47,
  "junit_methods": 3831,
  "artifact_attestation_verified": true,
  "scores": {
    "previous_overall": 9.0,
    "overall": 9.1,
    "categories": [
      {
        "name": "Security and access control",
        "score": 9,
        "reason": "Authenticated merchant recurrence terms, single-use base mandates and atomic agent occurrence caps join existing signature/cart/replay checks. Live custody remains unqualified.",
        "previous": 9,
        "assessment_note": "Historical score carried forward; not reassessed in this testing/documentation review."
      },
      {
        "name": "Observability and diagnosability",
        "score": 9.6,
        "reason": "Shared instrumentation now integrates six SDK HTTP hosts with coroutine-safe traces, authenticated metrics, bounded admission, connection-pool diagnostics, real authenticated OTLP export and exporter-backpressure evidence. Deployment SLO agreement, backend retention/access enforcement and actual on-call qualification remain open.",
        "previous": 9.6,
        "assessment_note": "Historical score carried forward; not reassessed in this testing/documentation review."
      },
      {
        "name": "Reliability and scale",
        "score": 9,
        "reason": "Budget and occurrence races, reconciliation rollback, replay and uncertain commit pass. Real backup/restore preserves the complete ledger snapshot; broad production load and PITR are not qualified.",
        "previous": 9,
        "assessment_note": "Historical score carried forward; not reassessed in this testing/documentation review."
      },
      {
        "name": "Configuration and data",
        "score": 9,
        "reason": "Idempotent terminal reconciliation, preserved replay/count state, legacy schema migration and unknown legacy ages are tested. External journal authentication and stale-backup recovery remain host responsibilities.",
        "previous": 9,
        "assessment_note": "Historical score carried forward; not reassessed in this testing/documentation review."
      },
      {
        "name": "Deployment and release",
        "score": 8.5,
        "reason": "Historical score retained. This review adds a committed SDK candidate and hosted validation; publishing and deployed release qualification remain separate.",
        "previous": 8.5,
        "assessment_note": "Historical score carried forward; not reassessed in this testing/documentation review."
      },
      {
        "name": "Testing and documentation",
        "score": 9.5,
        "reason": "Full local SDK build and exact-commit hosted release-evidence gates pass; merged coverage retains its floors; 26 Python vectors, three reverse profiles and a 214-step PostgreSQL model broaden conformance; nine source-backed examples and strict discovery, named-result, matrix and skip gates protect evidence. Full provider qualification and exhaustive supported-profile/snippet review remain outside this assessment.",
        "previous": 9.0
      }
    ],
    "rubric": "Same six equally weighted categories; only Testing and documentation reassessed. Engineering judgment, not certification.",
    "arithmetic": "54.6 / 6 = 9.1, rounded half-up to 9.1",
    "scope": "Testing/documentation qualification of the credential-free SDK candidate, with explicit optional provider exceptions; not universal conformance or production deployment certification.",
    "reassessment_basis": [
      "The previous full-build, merged-coverage and Docker evidence gaps are closed for this candidate.",
      "Hosted release evidence is bound to the exact committed source and retained with its artifacts.",
      "Independent-language conformance adds autonomous payment, signed checkout and sequential durable ledger behavior.",
      "Critical examples are exact copies of compiled/executed source; missing vectors, named regressions and unapproved skips fail CI.",
      "A 10.0 remains unwarranted while external custody/provider matrices, exhaustive supported-profile conformance and the wider snippet inventory remain incomplete."
    ]
  },
  "artifact_sha256": {
    "artifact-attestation.json": "ee377d74164e42efcca84f1722c0e2b392771db5f79ba248dc69b0a9ce3cfc59",
    "coverage-summary.json": "8f9423e07abc5c73731debd8a3198e0491421fb4eb94f06dec68adb8f45225e7",
    "documentation-execution.log": "2677db2273bd05ee6e8a4ec073f1425272166ecf9cc453187cba86c02691da34",
    "documentation.json": "e053717f8d10aff0f1a6762eb694c3fe4283716f12749f2885f60abbfd6ff7f5",
    "hosted-run.json": "cac1cf310372fdb3279450f7708911776760277a734d1e7102c39c3b15efc3ae",
    "hosted-validation-manifest.json": "78b9485df8a3dd6aa4f5e33919ac6042a3affd95d6a8480bb0772753261790db",
    "junit-contract.json": "f188d184965657973b662882a5a1e4c9e38a90f7dfc62e9ba62f38adeec639f2",
    "local-test-results.zip": "b9fb1c015422aca2084e72c7635ba31e6b7ab0b4a60c523327d6f279f91073cf",
    "local-validation-manifest.json": "d51a8a5f96fa0e0c81530c1f5f65a89b8f46c91345aee9c1368fcf9b142724db",
    "orphaned-report-audit.json": "db6c6b7050385ef77cf201d5cfffb5b7d74e72e738528a981abf0f3061053773",
    "reference-tests.xml": "73745c11ba0bf2afad3a2e27950dd463d01e1436d65e3a3fdae10fa0fb660655",
    "required-tests.json": "43437b20eef08332f55777724a690c66b5d1652bd991a0fc5d1ac31a951792c3",
    "source-comparison.json": "267b3c1502e3a68b42c02df40f59cf9e747b1c8a67814082a843507ac30ea4d8",
    "test-skip-policy.json": "8d3c5e7dcb1fd35f48572987a05d77388bb525e92d81f573e6935c140a95b618",
    "vi-autonomous-results.json": "fd430368bcc6bfe39ce9c94deddf79e6bbc490f2f3ee942701d72326c851da53",
    "vi-checkout-results.json": "e20cff53b6c7d632207dd820ddbbfc9717136815fa24f87c40f01103240eeaf0",
    "vi-immediate-results.json": "42fb87fc2f59d107d2f5f21e2523bc26741b032176b233b8e36acc497a63c7ee",
    "vi-matrix.json": "d15b8b9e7f120be80e00b1e3bb2178ea01a72b6c228c42256ca62ffc32c13224",
    "vi-python-autonomous-results.json": "bb7e12ee2c860e9a5cd3243f177de4cd66d2070e3f2ad6d96cecbfd3c4aae5c2",
    "vi-python-immediate-results.json": "6f21c66741a2006b118e40527e0be8a4c5b020ce8b147567b04fb77be7056969"
  }
}
