{"count":16,"artifacts":[{"artifact_id":"admitted_artifact_bee63c21e4e01b37eee59324","body":"Ratification requested for a pr_loop tested change.\nPR: cockpit: spent candidates render settled, never error/actionable (services#235 iOS leg)\nhead_sha: 5bda765f59e2ae444a93379bf8f3855dc2a7efbe\ntested_commit: 5bda765f59e2ae444a93379bf8f3855dc2a7efbe\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_2d472943e49c3035c29375ec","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"3c706c44e5f1485dfb95b7dbe4f41a602140f7f6f7f76566dddc42095669994d","chamber_sequence":7056,"error":"no installation discovered for repo 'fentonbenjamin/notmagic-ios'","failed_at":"2026-08-19T19:53:39.348931+00:00","head_sha":"5bda765f59e2ae444a93379bf8f3855dc2a7efbe","intake_id":"","post_status":"failed","pr_number":45,"repo":"fentonbenjamin/notmagic-ios","specimen_id":"specimen:pr_loop.ratification:gh:fentonbenjamin/notmagic-ios#45@5bda765f59e2","staged_at":"2026-08-19T19:53:38.691752+00:00","trace_id":""},{"artifact_id":"admitted_artifact_b6af2c2c220e08441ccaf181","body":"2 concerns. 6 open questions. 2 points look stable.\nverdict: not_ready\nfindings: 2\nreliance: /reliance/c0a2a8b5d058f14d864e235984a4739cfdc13f4220c9e56b67bc828cb7e1bb21\nchain: #149","candidate_id":"pr_review_finding_c3787c1a905f8353669818cc","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"e5e62ea90af9b3ceea678798cd35746482135e7521f02cb6a7eb1104376c4c72","chamber_sequence":6465,"github_comment_id":5295124342,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-5295124342","head_sha":"a511963a22a255a4ebfa3dddd7d8b04792301324","intake_id":"","post_status":"posted","posted_at":"2026-08-14T15:30:40.150657+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-08-14T15:30:39.072839+00:00","trace_id":""},{"artifact_id":"admitted_artifact_a23df06c469c7ef7b65f77e8","body":"2 concerns. 1 open question. 1 point looks stable.\nverdict: not_ready\nfindings: 2\nreliance: /reliance/699f76d38221d1ecb91fcf9810f0e937e5da262297039b8a4a5b6a44cc3c9466\nchain: #143","candidate_id":"pr_review_finding_cef0061ebd486f0cf54f4d1f","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"b87aeeafe8e05c7273f229e70711131c0e760eb3ee17612c68426b83aa1240b1","chamber_sequence":6134,"github_comment_id":5259729874,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-5259729874","head_sha":"f6578da9ceb93cac71aeed5e3821ea79f39226e9","intake_id":"","post_status":"posted","posted_at":"2026-08-11T22:46:04.908738+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-08-11T22:46:03.958283+00:00","trace_id":""},{"artifact_id":"admitted_artifact_9e7267bbbc3c0b819fd2eb9b","body":"Ratification requested for a pr_loop tested change.\nPR: pr loop: require phone candidate publication\nhead_sha: 23702ebe23c5ee6d557d0cd79f072c7a89c05012\ntested_commit: 23702ebe23c5ee6d557d0cd79f072c7a89c05012\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_547158ec10ddbf5887414f3d","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"128f24b8d6b7839f9bf7a97fd11032b3a47529385f8d3da7e4daecbf84e111ce","chamber_sequence":7120,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-20T01:08:50.477611+00:00","head_sha":"23702ebe23c5ee6d557d0cd79f072c7a89c05012","intake_id":"","post_status":"failed","pr_number":238,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#238@23702ebe23c5","staged_at":"2026-08-20T01:08:50.034702+00:00","trace_id":""},{"artifact_id":"admitted_artifact_9d7707dec61e77e86bf1c8ca","body":"Ratification requested for a pr_loop tested change.\nPR: gateway: an authorized candidate is SPENT — single-use guard (#235, MVP tranche 1)\nhead_sha: 24487d6a2c2d56d8b0bb95942e4a7d5fe9c1d5cb\ntested_commit: 24487d6a2c2d56d8b0bb95942e4a7d5fe9c1d5cb\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_d8d3eeae02b5e49c8f4baee7","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"b1c42aaf79f12c357d88530f669362f4f553237ca1897c744e3cc2cc3f1e83c6","chamber_sequence":7045,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-19T19:11:01.180631+00:00","head_sha":"24487d6a2c2d56d8b0bb95942e4a7d5fe9c1d5cb","intake_id":"","post_status":"failed","pr_number":236,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#236@24487d6a2c2d","staged_at":"2026-08-19T19:11:00.988875+00:00","trace_id":""},{"artifact_id":"admitted_artifact_94baee80b83f5720eed0d277","body":"Ratification requested for a pr_loop tested change.\nPR: pr loop: require phone candidate publication\nhead_sha: dfbbc3046e5f710ed7030bed71dc3c5f664f2d28\ntested_commit: dfbbc3046e5f710ed7030bed71dc3c5f664f2d28\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_562094c377c8852e72efcd4c","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"154267c7230e1b8dfaca542a67486ec74f3953d2c1356830bbae6ef247915f72","chamber_sequence":7070,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-19T22:20:21.705182+00:00","head_sha":"dfbbc3046e5f710ed7030bed71dc3c5f664f2d28","intake_id":"","post_status":"failed","pr_number":238,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#238@dfbbc3046e5f","staged_at":"2026-08-19T22:20:21.569054+00:00","trace_id":""},{"artifact_id":"admitted_artifact_90aaa5e7be308ddda71db3ee","body":"`X-Internal-Trust` is a client-controlled HTTP header. Anyone who can set headers — browser extensions, curl, upstream proxies, internal services with the wrong scope — can flip this branch. Treating it as authentication grants admin access to unauthenticated callers. The branch leads to `return NextResponse.json({ ok: true, as: user.id, admin: true });` — i.e., the caller is granted authority on the header's word alone. Fix: drop the header branch and enforce the real authorization check unconditionally. If you genuinely need internal services to bypass user-level checks, do it via a server-to-server credential the client cannot forge (mTLS, signed JWT with a private-key issuer, SPIFFE identity) — not a header value.","candidate_id":"pr_review_finding_fd631954be0fa37c7cd679ce","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"93e73938fea71d4d354b46aabaf4313b63f999ed63fe5b0a4479165e0979d556","chamber_sequence":3917,"github_comment_id":5029991013,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-5029991013","head_sha":"5d7d4b41f7c662597165e1be715370453e662e8c","intake_id":"","post_status":"posted","posted_at":"2026-07-21T03:59:33.051671+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-07-21T03:59:32.335361+00:00","trace_id":""},{"artifact_id":"admitted_artifact_9074ef570fd9ab1541ef9203","body":"2 concerns. 6 open questions. 2 points look stable.\nverdict: not_ready\nfindings: 2\nreliance: /reliance/ffa90c491c31ef1a86831a62c45e0c95da4ea71ed538a35b97e85c14aa4c9254\nchain: #151","candidate_id":"pr_review_finding_e441a722db0db75b5a2feb80","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"b5acb65df1092951f1a5c280eabc6a5db781af876407249be94240d3da2c235a","chamber_sequence":6133,"github_comment_id":5259727479,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-5259727479","head_sha":"fa7b9a41523626b1939b19cece89fd5ad5a195a0","intake_id":"","post_status":"posted","posted_at":"2026-08-11T22:45:44.868903+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-08-11T22:45:43.962956+00:00","trace_id":""},{"artifact_id":"admitted_artifact_71a885714addd496ef3a9acd","body":"This renders a `verified` UI label without enforcing all three proofs that the Stealthy Seal invariant requires: a live block, a chain entry, and chain-verify-pass. Label site: `return <Pill kind=\"verified\">verified ✓</Pill>;`. Only 1 canonical proof predicate(s) gate this label. Fixture data, snapshots, or missing chain context will render as verified — a stealthy seal. Fix: gate verified rendering on all three predicates together (`chain_verify_pass && entry_hash && live_chain_entry`, or the equivalent names in this codebase). Anything less and the label asserts more than the chain has earned.","candidate_id":"pr_review_finding_f820b8f231d4e2bfdb47b188","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"e347a2c53173ad3f5c1a6b8ecd4bc55db31593de2148d175fe34607ce04f9202","chamber_sequence":3920,"github_comment_id":5030127743,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-5030127743","head_sha":"a511963a22a255a4ebfa3dddd7d8b04792301324","intake_id":"","post_status":"posted","posted_at":"2026-07-21T04:22:47.226225+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-07-21T04:22:46.523553+00:00","trace_id":""},{"artifact_id":"admitted_artifact_584be7920a3ad62bacff8752","body":"Critical: This exports a non-terminating loop (`while (true) {`) from runtime code at `lib/infinite-loop.ts:3`. Any caller pins the event loop / process with no callable workaround — including callers in production. Fix: move the construct to a test fixture or harness, OR add an explicit exit condition (await, sleep, break, return, throw, yield, process.exit). If the loop is intentional external-detection bait, mark the file path under `/fixtures/` or `/tests/` so it stays out of runtime.","candidate_id":"pr_review_finding_2503b821454e9beaad357961","candidate_kind":"pr_review_finding","chamber_admission_kind":"human_authorization","chamber_block_id":"7638e35f18d039063e419b9e6c28eab0c2cdde49547f621cd69f01124d7d5ed9","chamber_sequence":163,"github_comment_id":4537763940,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/11#issuecomment-4537763940","head_sha":"d347ad865b9dfec450b1e18baee954ff7397e3ed","intake_id":"i_4e7b9d81cbe3ea59","post_status":"recovered","pr_number":11,"recovered_at":"2026-05-26T04:08:49.584797+00:00","recovered_via_comp_id":"comp_11176328f5ac73b5437375cd","recovery_method":"chain_and_github_verification","repo":"fentonbenjamin/shape","specimen_id":"specimen:smell_check.farm.infinite_loop:gh:fentonbenjamin/shape#11@d347ad865b9d","staged_at":"2026-05-26T04:08:49.565732+00:00","trace_id":"trace:i_4e7b9d81cbe3ea59"},{"artifact_id":"admitted_artifact_4458155fcb65efdaf9d577fd","body":"Ratification requested for a pr_loop tested change.\nPR: formations: material bound into formation root + raw model output retained in bound log\nhead_sha: bbd7213ef0c4575da0c8bab6d82a57b69b75a1f8\ntested_commit: bbd7213ef0c4575da0c8bab6d82a57b69b75a1f8\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_d0c8c54173746fd785ac0fcd","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"ef790a06ad303adb9cfb2f2fb4f89ae115ebdf4e151df92de922da65f23d1456","chamber_sequence":7027,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-19T16:06:34.713304+00:00","head_sha":"bbd7213ef0c4575da0c8bab6d82a57b69b75a1f8","intake_id":"","post_status":"failed","pr_number":234,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#234@bbd7213ef0c4","staged_at":"2026-08-19T16:06:34.549226+00:00","trace_id":""},{"artifact_id":"admitted_artifact_35d5374c64b1791b73db585c","body":"Ratification requested for a pr_loop tested change.\nPR: gateway: make candidate queues actor-private by default\nhead_sha: f7e9438ed9e5e98a7b744fa11407277dc2ff01a2\ntested_commit: f7e9438ed9e5e98a7b744fa11407277dc2ff01a2\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_c26af3e04a6515a801ee95b4","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"e3a525fd822461a3d6e63224a94dd23f6c5d003720712bd0058235f8855fdb11","chamber_sequence":7121,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-20T01:09:35.945078+00:00","head_sha":"f7e9438ed9e5e98a7b744fa11407277dc2ff01a2","intake_id":"","post_status":"failed","pr_number":239,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#239@f7e9438ed9e5","staged_at":"2026-08-20T01:09:35.801275+00:00","trace_id":""},{"artifact_id":"admitted_artifact_2c5327b0bff346e815ef5537","body":"Ratification requested for a pr_loop tested change.\nPR: formations: case-world fix + real default-path smoke tests + frontier_seat tracer launcher\nhead_sha: 9ca47d5616867b22c2bdc27a5560fe85e8894a7c\ntested_commit: 9ca47d5616867b22c2bdc27a5560fe85e8894a7c\nApproving records a hardware-attested human ratification of this tested change on the admission chain and posts this comment to the PR. It does NOT merge the PR — the merge remains the operator's literal MERGE in the pr_loop steward.","candidate_id":"pr_review_finding_522b4df1db7543c510641bab","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"156c33e1b527c46b3f7a5d3f77be8768a27aed9c7c4717e8a4a2096de3d323f6","chamber_sequence":7023,"error":"no installation discovered for repo 'fentonbuttonshop/notmagic-services'","failed_at":"2026-08-19T15:35:24.270429+00:00","head_sha":"9ca47d5616867b22c2bdc27a5560fe85e8894a7c","intake_id":"","post_status":"failed","pr_number":233,"repo":"fentonbuttonshop/notmagic-services","specimen_id":"specimen:pr_loop.ratification:gh:fentonbuttonshop/notmagic-services#233@9ca47d561686","staged_at":"2026-08-19T15:35:24.081523+00:00","trace_id":""},{"artifact_id":"admitted_artifact_10c3f781ce56a0e7b12c529d","body":"`X-Internal-Trust` is a client-controlled HTTP header. Anyone who can set headers — browser extensions, curl, upstream proxies, internal services with the wrong scope — can flip this branch. Treating it as authentication grants admin access to unauthenticated callers. The branch leads to `return NextResponse.json({ ok: true, admin: true, result });` — i.e., the caller is granted authority on the header's word alone. Fix: drop the header branch and enforce the real authorization check unconditionally. If you genuinely need internal services to bypass user-level checks, do it via a server-to-server credential the client cannot forge (mTLS, signed JWT with a private-key issuer, SPIFFE identity) — not a header value.","candidate_id":"pr_review_finding_a7518a86d68745744e797086","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"872f7ab58d4b210dcacefd4e1c3275a152acf0644471cefea3a5223c0fa9bb19","chamber_sequence":166,"github_comment_id":4593882293,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-4593882293","head_sha":"fa7b9a41523626b1939b19cece89fd5ad5a195a0","intake_id":"","post_status":"posted","posted_at":"2026-06-01T15:08:11.216664+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-06-01T15:08:10.043145+00:00","trace_id":""},{"artifact_id":"admitted_artifact_0fc11f0b52f04d0217ff337e","body":"`X-Internal-Trust` is a client-controlled HTTP header. Anyone who can set headers — browser extensions, curl, upstream proxies, internal services with the wrong scope — can flip this branch. Treating it as authentication grants admin access to unauthenticated callers. The branch leads to `return NextResponse.json({ ok: true, as: user.id, admin: true });` — i.e., the caller is granted authority on the header's word alone. Fix: drop the header branch and enforce the real authorization check unconditionally. If you genuinely need internal services to bypass user-level checks, do it via a server-to-server credential the client cannot forge (mTLS, signed JWT with a private-key issuer, SPIFFE identity) — not a header value.","candidate_id":"pr_review_finding_59cec661c4466504ae6fe61b","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"af918e005f1cf57f6bc2b82cca37f9b36ad92649e407005f068ff7230b1b04d4","chamber_sequence":165,"github_comment_id":4581224491,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-4581224491","head_sha":"fa7b9a41523626b1939b19cece89fd5ad5a195a0","intake_id":"","post_status":"posted","posted_at":"2026-05-30T01:46:44.440723+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-05-30T01:46:43.715380+00:00","trace_id":""},{"artifact_id":"admitted_artifact_0c8a2373b0b65f628f13e8aa","body":"This renders a `verified` UI label without enforcing all three proofs that the Stealthy Seal invariant requires: a live block, a chain entry, and chain-verify-pass. Label site: `return <Pill kind=\"verified\">verified ✓</Pill>;`. Only 1 canonical proof predicate(s) gate this label. Fixture data, snapshots, or missing chain context will render as verified — a stealthy seal. Fix: gate verified rendering on all three predicates together (`chain_verify_pass && entry_hash && live_chain_entry`, or the equivalent names in this codebase). Anything less and the label asserts more than the chain has earned.","candidate_id":"pr_review_finding_06083c63ceedc5a5e18cab03","candidate_kind":"pr_review_finding","chamber_admission_kind":"","chamber_block_id":"2ea3b0e19b1d5995978c500d9e0ada854bd8d3540e6b585acf09ca243e69d6fa","chamber_sequence":164,"github_comment_id":4581168972,"github_comment_url":"https://github.com/fentonbenjamin/shape/pull/10#issuecomment-4581168972","head_sha":"fa7b9a41523626b1939b19cece89fd5ad5a195a0","intake_id":"","post_status":"posted","posted_at":"2026-05-30T01:35:34.884726+00:00","pr_number":10,"repo":"fentonbenjamin/shape","specimen_id":"","staged_at":"2026-05-30T01:35:34.122568+00:00","trace_id":""}]}